Human Risks

Denmark · owned by MM 18 Holding ApS (Denmark) · humanrisks.com · 11 vendors

Human Risks is a Danish SaaS company that provides an all-in-one security risk management platform for enterprise organizations. The platform covers risk assessments, incident reporting, business continuity planning, mass communications, and compliance management in a single unified tool. It serves clients across industries including banking, pharmaceuticals, manufacturing, and retail, with customers such as IKEA, HSBC, and GSK.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-13 · revision 3

11 direct vendors, 202 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Human Risks demonstrates a good level of migration readiness, primarily due to its modern core technology stack. The extensive use of Microsoft Azure for cloud hosting, coupled with Azure Key Vault, REST APIs, and AI-powered automation, indicates a cloud-centric architecture that is inherently more adaptable to migration efforts, especially within the Azure ecosystem or to other public cloud providers. The company's established compliance frameworks (GDPR, ISO 27001, NIS2, CER) suggest a mature approach to data governance and security, which, while requiring careful planning, can facilitate a compliant migration process. However, several factors introduce uncertainty and potential challenges. The absence of specified 'Data Residency Requirements' is a significant unknown; if strict requirements exist, they could severely limit migration options and increase complexity. The 'Vendor Lock-in Risk' is also unknown, particularly concerning their deep integration with Microsoft Azure. While Azure provides flexibility, a strategic decision to migrate away from Azure to a different cloud provider could entail substantial effort and cost. Furthermore, the lack of public financial data (revenue trends, growth) makes it difficult to assess the company's financial capacity to fund a potentially large-scale migration project. The presence of 'Total Services: 14' implies numerous third-party integrations (e.g., Intercom, HubSpot, MailChimp, PostHog) that would require careful planning for data migration, re-integration, and ensuring business continuity during any platform shift.

Compliance

4 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

As a Danish company processing personal data of employees, customers, and platform users, GDPR compliance is mandatory. The company demonstrates strong compliance with comprehensive privacy policy, data processing agreements, appointed IT-Governance Owner (DPO equivalent), regular policy reviews, and detailed data handling procedures. Risk level is Medium rather than Low due to the nature of their business handling sensitive security data and the significant penalties for non-compliance (up to 4% of annual turnover).

Evidence: https://humanrisks.com/information/privacy/, https://humanrisks.com/wp-content/uploads/2024/04/Security-White-Paper_V1.9_2024.04.29_HumanRisks1.pdf

NIS2 (source) — Assessment Required

NIS2 applicability is uncertain. While Human Risks provides cybersecurity services and could potentially fall under 'digital service providers' or 'ICT service management' categories, their specific classification as Essential or Important Entity is unclear. The company appears to meet size thresholds (established since 2015 with notable clients like IKEA, GSK, HSBC), but definitive sector classification requires further assessment. Non-compliance penalties can be significant (up to €10M or 2% of turnover).

Evidence: https://humanrisks.com

SOC 2 (source) — Assessment Required

As a SaaS provider handling customer data, SOC2 compliance would be highly beneficial for customer trust and competitive positioning. Many enterprise clients expect SOC2 reports from their vendors. While not legally mandatory, lack of SOC2 compliance could impact business opportunities and customer confidence, especially given their enterprise client base including major corporations.

Evidence: https://humanrisks.com/wp-content/uploads/2024/04/Security-White-Paper_V1.9_2024.04.29_HumanRisks1.pdf

Financials

Three-year financials

Financial Resilience Score: 5/10

Human Risks is a private Danish SaaS company in the enterprise security risk management (ESRM) space with no publicly verifiable financial data accessible in this research session. The company shows strong qualitative indicators of resilience, including a high-profile enterprise customer base (IKEA, GSK, HSBC, Maersk, Energinet, Crane, Yondr) that typically delivers multi-year SaaS contracts with strong gross margins. A stated 96% retention rate, if accurate, suggests low churn and stable recurring revenue—a positive signal for SaaS unit economics. Regulatory tailwinds from EU directives (NIS2, CER, DORA) drive demand among critical-infrastructure and regulated enterprises, which is Human Risks' core ICP. However, the company faces meaningful risks. It operates in a highly competitive GRC/ESRM market against far larger and better-capitalized incumbents like Resolver, Riskonnect, LogicGate, OneTrust, ServiceNow GRC, Archer, and Diligent. As a likely VC- or growth-funded ApS at scale-up stage, the company is probably still investing heavily in growth and may be loss-making, with funding dependence and runway being critical concerns. Customer concentration risk is notable given a handful of marquee logos likely dominate ARR, and international customers create FX exposure (GBP/SEK/EUR vs DKK). A midpoint score reflects the balance between strong qualitative signals and the absence of verifiable financial data.

Key strengths: High-profile enterprise customer base (IKEA, GSK, HSBC, Maersk, Energinet, Crane, Yondr), Stated 96% customer retention rate indicating low churn, Regulatory tailwinds from EU NIS2, CER Directive, and DORA, Vertical breadth across banking, pharma, manufacturing, professional services, data centres, Integrated SaaS platform with 8 modules aligned with ISO 31000

Risk factors: Highly competitive market with larger, better-capitalized competitors (Resolver, Riskonnect, OneTrust, ServiceNow GRC), Likely still scaling and potentially loss-making as a growth-stage SaaS, Funding dependence and runway risk as a VC/growth-funded ApS, Customer concentration risk—loss of one or two marquee logos could materially affect revenue, FX exposure to GBP/SEK/EUR against DKK reporting currency, Small private company with limited public financial transparency

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report