Dubex A/S
Denmark · owned by Conscia Group (Sweden) · dubex.dk · 33 vendors
Dubex is a full-service cybersecurity company with over 25 years of experience, providing comprehensive security solutions including risk management, security operations, incident response, offensive security, and cybersecurity training. The company helps organizations strengthen security and enable growth through expert consulting, managed security services, and technical security solutions.
Resilience scores
- Digital Sovereignty: 15
- Digital Resilience: 6
- Financial Resilience: 4
Disruption prediction
Dubex A/S has an estimated 17% probability of disruption in the next 6 months.
14 of Dubex A/S's 33 vendors monitored for disruptions.
Technology vendors
- Constant Contact — Media & Marketing — United States
- Netlify, Inc. — Technology — United States
- Zscaler, Inc. — Cybersecurity — United States
- and 30 more
Services catalogue
1 service in catalogue across 1 category; runs on 33 sub-vendors.
- Cybersecurity services
Insights
Last updated 2026-09-13 · revision 28
33 direct vendors, 299 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 1
- Israel: 1
- Japan: 1
Subvendors by controlling owner country (sample)
- Taiwan: 1
- Romania: 1
- Norway: 5
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Dubex A/S exhibits medium migration readiness, primarily due to significant unknowns regarding key technical and vendor-related factors. A critical lack of information on their internal tech stack (e.g., cloud-native adoption, containerization, microservices) makes it challenging to assess the technical complexity and effort required for migration. Data residency requirements are also a concern; while data is inferred to be hosted within the EU for GDPR, specific data center locations or explicit data residency options are not publicly disclosed, and confidence in this information is low. This ambiguity poses a significant planning hurdle for any cloud migration strategy. The 'Vendor Lock-in Risk' is unknown, and the number of distinct vendors is not specified (despite 45 services and diverse vendor countries), which is crucial for understanding potential dependencies and the complexity of migrating away from existing services. The regulatory environment, including GDPR and NIS2 applicability, while indicating strong compliance processes, also introduces strict requirements that must be meticulously managed during migration, potentially increasing complexity. On the positive side, consistent revenue growth suggests a potential financial capacity to fund migration initiatives. However, without clearer insights into their technology landscape, vendor dependencies, and precise data residency needs, migration readiness remains constrained.
Compliance
4 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
GDPR applies to all EU-based companies processing personal data. As a Danish technology company, Dubex A/S is subject to GDPR with high certainty. Non-compliance can result in fines up to 4% of annual global turnover or €20 million. Technology companies typically process significant amounts of personal data (employee, customer, user data), making compliance critical. Danish Data Protection Agency actively enforces GDPR.
NIS2 (source) — Assessment Required
NIS2 applicability depends on specific technology sector and company size. If Dubex A/S provides digital services, ICT services, or operates as a digital provider with 50+ employees or €10M+ turnover, they would be classified as Important Entities under NIS2. Technology companies often fall under digital infrastructure or ICT service management categories. Non-compliance can result in significant penalties and operational restrictions.
ISO 27001 (source) — Assessment Required
ISO 27001 is highly relevant for technology companies as it demonstrates systematic approach to information security management. While voluntary, it's increasingly expected by enterprise customers and partners. Medium risk as lack of certification may impact business opportunities and customer trust, though not legally mandated.
Financials
Three-year financials
- 2025: revenue DKK 134.5M, EBIT DKK 4.0M, equity DKK 14.1M
- 2024: revenue DKK 111.4M, EBIT DKK -0.02M, equity DKK 10.2M
- 2023: revenue DKK 116.1M, EBIT DKK 1.2M, equity DKK 10.2M
Financial Resilience Score: 4/10
Dubex A/S shows a mixed resilience profile. On the positive side, the company demonstrated a strong recovery in FY2024/25 with revenue growth of ~21% to DKK 134.5M and EBIT rebounding to DKK 4.0M after a near break-even prior year. The company operates in the structurally growing cybersecurity sector, has over 25 years of niche expertise, and had strategic value that led to its acquisition by Conscia Danmark A/S. Equity grew 38% in FY2024/25 to DKK 14.1M via retained earnings. However, several factors weigh on the resilience score. The equity base is very thin (DKK 10-16M) relative to revenue exceeding DKK 100M, providing limited cushion against downturns. Profitability has been highly volatile over 13 years, swinging between DKK 6M losses (2016, 2019) and DKK 8M profits (2020). Staff costs of DKK 54M consume nearly all gross profit, making the cost structure inflexible. Revenue is essentially single-country (Denmark), and the historical revenue trajectory shows no strong secular growth—FY2025 revenue is still below the 2020 peak of DKK 161M. Most importantly, Dubex A/S was dissolved after merger into Conscia Danmark A/S on 29 December 2025, so it no longer exists as a standalone entity. This eliminates its standalone credit or investment relevance going forward, though the underlying business continues within Conscia.
Key strengths: Strong FY2024/25 revenue rebound of ~21% to DKK 134.5M, EBIT recovery from near-zero to DKK 4.0M in FY2024/25, Equity grew 38% to DKK 14.1M via retained profit, Over 25 years of specialist cybersecurity expertise, Strategic value validated by Conscia acquisition, Improving gross margin (~44% in FY2024/25) reflecting services mix shift
Risk factors: Thin equity base (DKK 10-16M) relative to DKK 100M+ revenue, Highly volatile profitability with multiple loss years historically, Staff cost intensity (~DKK 54M) consumes most of gross profit, Single-country revenue concentration in Denmark, No secular revenue growth—FY2025 below 2020 peak of DKK 161M, Entity legally dissolved after merger on 29 December 2025, Lumpy product resale creates earnings volatility
Revenue by geography
- Denmark: 100%
Workforce by country
- Denmark: 80
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.