DLX A/S
Denmark · owned by MAKS Holding Herning ApS (Denmark) · www.dlx.dk · 7 vendors
Resilience scores
- Digital Sovereignty: 14
- Digital Resilience: 6
- Financial Resilience: 7
Technology vendors
- Fortinet, Inc. — Technology — United States
- Palo Alto Networks, Inc. — Technology — United States
- TeamViewer AG — Technology — Germany
- and 4 more
Services catalogue
3 services in catalogue across 2 categories; runs on 7 sub-vendors.
- DNS Hosting
- Personal Data Processing
- Web Hosting
Insights
Last updated 2026-09-13 · revision 3
7 direct vendors, 118 subvendors
Direct vendors by controlling owner country (sample)
- United States: 6
- Germany: 1
Subvendors by controlling owner country (sample)
- Sweden: 3
- United States: 97
- Denmark: 1
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
DLX A/S exhibits moderate migration readiness. The company's strong financial stability, indicated by an AAA credit rating, provides a solid foundation to fund potential migration initiatives. Their existing ISAE 3402 assurance report demonstrates a mature control environment, which can be leveraged to ensure security and compliance in a new cloud setting. Furthermore, DLX's experience in managed IT services and IT consulting, coupled with their resale of Microsoft Office 365, indicates some familiarity with cloud operations and the ability to manage complex IT projects. However, several factors present significant challenges to migration. DLX's core infrastructure, including datacenter operations, virtual servers built on VMware, and web hosting on FreeBSD, represents a traditional, on-premises architecture. A full migration to a cloud-native environment would likely require substantial re-platforming and re-architecture rather than a simple lift-and-shift, increasing complexity and cost. Strict data residency requirements, mandating data storage within Denmark/EU, significantly limit the choice of cloud providers and specific regions, adding a layer of complexity to planning and execution. Moreover, the identified regulatory compliance gaps, particularly concerning GDPR, NIS2, and ePrivacy, would need to be thoroughly addressed and re-validated in any new cloud environment to avoid legal and financial penalties. Finally, reliance on key vendor platforms like VMware, Acronis, and Veeam suggests a moderate level of vendor lock-in, which could complicate transitioning to alternative cloud-native services or require significant integration efforts.
Compliance
10 in-scope frameworks identified; showing 3.
ISAE 3000 (source) — Assessment Required
ISAE 3000 is the general framework for assurance engagements other than audits or reviews of historical financial information. ISAE 3402 (which DLX holds) is a specific application of ISAE 3000 principles. DLX may also be subject to ISAE 3000 in the context of ESG reporting assurance (they publish an ESG report) or other non-financial assurance engagements. Risk is Low as this is not a legally mandated framework and DLX's ISAE 3402 already demonstrates engagement with the ISAE assurance family.
Evidence: https://www.dlx.dk/revisionserklaering, https://dlx.dk/DLX_ISAE3402_2026.pdf, https://dlx.dk/esg
Danish IT Security Act — Assessment Required
Denmark has implemented EU NIS and NIS2 directives through national legislation. As a Danish IT infrastructure and managed services provider, DLX A/S may be subject to sector-specific cybersecurity obligations under Danish law. The Danish Business Authority (Erhvervsstyrelsen) and the Centre for Cyber Security (CFCS) are the primary enforcement bodies. Risk is Medium pending size threshold confirmation.
Evidence: https://www.erhvervsstyrelsen.dk/nis2, https://www.cfcs.dk/en/, https://www.dlx.dk
GDPR (source) — Partially Compliant
DLX A/S is headquartered in Denmark (EU member state) and operates as a cloud/IT services provider that acts as both a data controller (for its own customer and employee data) and a data processor (processing personal data on behalf of its customers via hosted services, virtual servers, online backup, hosted desktop, etc.). As a data processor for potentially many Danish and EU businesses, DLX carries elevated GDPR risk: any breach or non-compliance could affect multiple downstream data subjects. The Danish Data Protection Authority (Datatilsynet) is an active enforcement body. While DLX publicly offers a Data Processing Agreement (Databehandleraftale) — a positive compliance signal — the absence of a publicly visible privacy policy, DPO appointment disclosure, or Records of Processing Activities (RoPA) on their website introduces residual risk. Fines under GDPR can reach €20M or 4% of global annual turnover.
Evidence: https://www.dlx.dk/databehandleraftale, https://dlx.dk/DLXDatabehandleraftale.pdf, https://www.datatilsynet.dk/english, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
Financials
Three-year financials
- 2025: gross profit DKK 27.5M, EBIT DKK 12.4M, equity DKK 42.0M
- 2024: gross profit DKK 28.6M, EBIT DKK 13.5M, equity DKK 39.7M
- 2023: gross profit DKK 20.5M, EBIT DKK 10.7M, equity DKK 11.4M
Financial Resilience Score: 7/10
DLX A/S displays several qualitative indicators of financial solidity despite the absence of retrievable quantitative data in this session. The company holds a AAA credit-rating badge (typically issued by Bisnode/Dun & Bradstreet), which in the Danish rating system requires multi-year profitable trading, positive equity, and no payment remarks. This signals strong creditworthiness at the time of rating. Additionally, DLX maintains an ISAE 3402 assurance report, a recurring third-party audit standard for service organisations, implying mature internal controls and stable operations required by enterprise customers. The business model itself supports resilience: hosting, virtual servers, Microsoft 365, backup, and cloud PBX services are subscription-based, producing predictable recurring cash flow and high customer stickiness. Ownership of a physical datacenter in Herning provides a defensible operational moat versus resellers, and a diversified multi-product portfolio (compute, storage, collaboration, telephony, web, advisory) reduces single-product dependence. As an A/S, DLX also meets higher governance and disclosure obligations, with minimum share capital of DKK 400,000. However, risks include exposure to a small, competitive Danish IT-hosting market dominated by larger players (GlobalConnect, Zitcom, Interxion) and hyperscalers (Azure, AWS, GCP). Capex intensity from owning a datacenter, energy-cost volatility (2022-2024), potential customer concentration, key-person risk typical of owner-managed A/S companies, and hyperscaler substitution risk for M365/IaaS workloads all temper the resilience score.
Key strengths: AAA credit-rating badge displayed on corporate website, ISAE 3402 assurance report indicating mature internal controls, Recurring subscription-based revenue model with high stickiness, Owned datacenter infrastructure in Herning as defensible moat, Diversified multi-product portfolio across hosting, M365, telephony, advisory, VMware Partner and Microsoft Partner certifications, A/S legal structure with minimum DKK 400,000 share capital and governance requirements
Risk factors: Small Danish IT-hosting market with structural price pressure, Competition from larger players (GlobalConnect, Zitcom, Interxion) and hyperscalers (Azure, AWS, GCP), Capex intensity from datacenter ownership including depreciation and hardware refresh, Energy-price volatility impacting datacenter operations, Potential customer concentration risk typical of small B2B IT providers, Key-person risk typical of owner-managed Danish A/S companies, Hyperscaler substitution risk for Office 365 and virtual server workloads
Revenue by geography
- Denmark: 100%
Revenue by product/service
- IT advisory: 0%
- Microsoft 365: 0%
- IT outsourcing: 0%
- Web hosting & domains: 0%
- IP-telephony (SIP, cloud PBX): 0%
- Datacenter (server hosting, virtual servers, hosted desktop, backup, co-location): 0%
Workforce by country
- Denmark: 20
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.