Dediko A/S

Denmark · owned by HIH FS AS (Norway) · dediko.dk · 39 vendors

Dediko A/S is a Danish cybersecurity firm headquartered in Albertslund, Denmark, specialising in IT security strategy, advisory, and managed services. The company offers both defensive services (such as Managed Detection and Response, Dark Web Monitoring, and AD Hardening) and offensive services (such as penetration testing, phishing tests, and vulnerability scanning). Since the year 2000, Dediko has also delivered software, support, and implementation services, along with compliance guidance (CIS, NIS2) and cybersecurity training for organisations of all sizes.

Resilience scores

Disruption prediction

Dediko A/S has an estimated 17% probability of disruption in the next 6 months.

8 of Dediko A/S's 39 vendors monitored for disruptions.

Technology vendors

Insights

Last updated 2026-09-13 · revision 2

39 direct vendors, 363 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Dediko A/S demonstrates a medium level of migration readiness. A key advantage is the absence of specified data residency requirements, which removes a common hurdle for cloud migrations. Their existing internal tech stack already incorporates several Software-as-a-Service (SaaS) solutions like MailChimp, Cloudflare, LinkedIn, and YouTube, indicating a familiarity with cloud-based services and a hybrid operational model. The stated vendor geographic diversity across 6 unique countries also suggests a potentially flexible vendor ecosystem, although the 'Total Vendors: 0' data point is contradictory and assumed to be an error. However, significant challenges exist. The core website runs on WordPress, which, depending on its configuration and hosting, may not be inherently cloud-native or easily adaptable to modern containerized or microservices architectures without significant refactoring. The ability to fund a migration is unclear due to missing financial data (revenue concentration, growth history). The 'Vendor Lock-in Risk' is unknown, making it difficult to assess potential complexities in disentangling from existing vendor contracts or proprietary systems. While they provide NIS2 advisory, the specific regulatory obligations for Dediko A/S itself are not determined, which could introduce unforeseen compliance requirements during a migration. The lack of explicit information on their internal adoption of cloud-native technologies (beyond SaaS) or containerization also points to a potentially traditional infrastructure that would require substantial effort to modernize.

Compliance

7 in-scope frameworks identified; showing 3.

ePrivacy Directive — Partially Compliant

The EU ePrivacy Directive (2002/58/EC, as amended) and its Danish implementation (the Danish Executive Order on Cookies, Bekendtgørelse nr. 1148 af 9. december 2011, as updated) require informed consent for non-essential cookies. Dediko A/S operates a website (dediko.dk) that uses cookies, has a separate cookie policy page, and references cookie consent in their privacy policy. The risk is Low because: (1) Dediko has a published cookie policy; (2) the company appears aware of consent requirements; (3) as a small website primarily serving B2B clients, cookie compliance risk is lower than for consumer-facing platforms; (4) however, full technical compliance of the cookie consent mechanism cannot be verified without a live audit of the website's consent management platform.

Evidence: https://dediko.dk/cookiepolitik/, https://dediko.dk/privatlivspolitik/, https://www.datatilsynet.dk/english/guidance/cookies

NIS2 (source) — Assessment Required

NIS2 applicability for Dediko A/S is nuanced and requires formal assessment for two distinct reasons: (1) As a Managed Security Service Provider (MSSP) offering Managed Detection and Response (MDR), Dark Web Monitoring, penetration testing, and security advisory services, Dediko may qualify as an Essential Entity under NIS2 Annex I, Section 8 ('ICT service management (B2B)'), which explicitly includes managed security service providers — notably, this category has NO size threshold exemption under NIS2. (2) Even if not classified as an MSSP under Annex I, Dediko could qualify as an Important Entity under Annex II as a digital provider or ICT service provider if it meets the medium enterprise threshold (50+ employees OR €10M+ turnover). The risk is rated Medium because: the MSSP classification is plausible given their MDR and 24/7 monitoring services, but Dediko appears to be a small/micro enterprise (single named director, small office address) that may fall below the 50-employee/€10M threshold for Important Entity classification. However, the MSSP carve-out from size thresholds means this cannot be dismissed. The Danish NIS2 implementing legislation (Lov om foranstaltninger til sikring af et højt fælles cybersikkerhedsniveau, L 111) entered into force in 2024. Enforcement risk is elevated given Dediko's sector and the Danish Centre for Cyber Security (CFCS) active oversight role.

Evidence: https://dediko.dk/compliance/nis2-raadgivning/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.cfcs.dk/en/, https://www.retsinformation.dk/eli/lta/2024/639

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for Information Security Management Systems (ISMS) and is highly relevant for cybersecurity service providers. Dediko A/S, as a company offering MDR, penetration testing, security advisory, and managed security services, handles sensitive client security data and has access to client IT environments. ISO 27001 certification would be a strong trust signal and is increasingly expected by enterprise clients and in procurement processes. The risk is rated Medium because: (1) ISO 27001 is voluntary but industry-standard for cybersecurity firms; (2) absence of certification may limit Dediko's ability to win larger contracts or public sector tenders in Denmark (where ISO 27001 is often a procurement requirement); (3) as a cybersecurity company, clients reasonably expect Dediko to practice what it preaches; (4) the Danish government and larger enterprises increasingly require ISO 27001 from IT security suppliers. The reputational and commercial risk of non-certification is notable for a cybersecurity firm.

Evidence: https://dediko.dk/compliance/cis/, https://dediko.dk/om-os/, https://www.iso.org/standard/27001, https://www.ds.dk/da/standarder/it/informationssikkerhed/ds-en-iso-iec-270012022

Financials

Three-year financials

Financial Resilience Score: 5/10

Dediko A/S (formerly Draware A/S, CVR 18663295) is a long-established Danish cybersecurity specialist with over 25 years of operating history since year 2000. The company benefits from a diversified vendor portfolio of 30+ cybersecurity brands, recurring-revenue services (MDR, dark web monitoring, subscription resale, training), and strong regulatory tailwinds from NIS2 compliance demand across Danish critical infrastructure sectors. Its A/S legal form provides a minimum statutory equity cushion of DKK 400,000-500,000. However, the company is a small-cap Danish specialist with likely modest absolute revenue and limited buffers against downturns, key-personnel loss, or customer churn. There is notable vendor concentration on ManageEngine as the primary product line on the resale side. Talent scarcity in Danish cybersecurity engineering creates wage inflation pressure squeezing services margins, and competitive pressure comes from larger Nordic MSSPs (Dubex, Trifork Security, Improsec, NNIT Cyber, Truesec, Orange Cyberdefense) and Big4 consulting arms. As a Danish class-B reporter, revenue is often not published, making external credit assessment harder. Specific numeric revenue, EBIT, equity, and employee counts for recent fiscal years could not be retrieved in this session and would need to be pulled from datacvr.virk.dk filings. A midpoint resilience score reflects the balance between durable market position and small-company/disclosure-opacity risks.

Key strengths: 25+ year operating history since 2000 in Danish IT security, Diversified vendor portfolio of 30+ cybersecurity brands, Recurring-revenue services (MDR, Dark Web Monitoring, subscriptions, training), Regulatory tailwind from NIS2 advisory demand, A/S legal form with statutory minimum share capital cushion, Broad service mix across defensive, offensive, compliance, and training

Risk factors: Small-cap Danish specialist with likely modest revenue and limited downturn buffer, Vendor concentration on ManageEngine as main product supplier, Cybersecurity talent scarcity and wage inflation in Denmark, Competitive pressure from larger Nordic MSSPs and Big4 consulting arms, Disclosure opacity as class-B reporter (revenue often not published), Key-personnel risk typical of small specialist firms, Geographic concentration in Denmark only

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report