IT-Afdelingen A/S
Denmark · www.itafdelingen.net · 22 vendors
IT-Afdelingen A/S is a Danish outsourcing company that provides computer programming, consultancy, and computer facilities management activities. The company offers services such as outsourcing, hosting, and internet access to businesses. They also provide 24/7 support to their clients.
Resilience scores
- Digital Sovereignty: 36
- Digital Resilience: 4
Technology vendors
- ConnectWise — Technology — United States
- Telia Eesti AS — Telecommunications — Estonia
- Veeam Software Group GmbH — Technology — United States
- and 19 more
Services catalogue
3 services in catalogue across 1 category; runs on 22 sub-vendors.
- Email Security/Relay
- Email Service
- IT Services
Insights
Last updated 2026-07-03 · revision 7
22 direct vendors, 281 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 2
- Belgium: 2
- Japan: 1
Subvendors by controlling owner country (sample)
- Japan: 4
- Cyprus: 1
- United Kingdom: 7
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
IT-Afdelingen A/S demonstrates low migration readiness, primarily due to a complex regulatory landscape and a high number of services. The company faces mandatory compliance requirements under GDPR and potentially NIS2, both of which impose strict data protection, security, and incident reporting obligations that must be meticulously addressed during any migration. Furthermore, GDPR's data residency requirements for EU personal data add significant complexity, necessitating careful planning for data transfers and ensuring adequate safeguards, especially when considering non-EU cloud providers. The utilization of 39 services suggests a substantial and potentially intricate operational environment. Migrating such a large number of services would likely involve extensive planning, dependency mapping, data migration, and integration efforts, posing a significant challenge. The lack of information regarding the company's internal tech stack (e.g., cloud-native adoption, containerization, microservices) prevents an assessment of its architectural flexibility. Similarly, financial stability and specific vendor lock-in risks remain unknown, which are critical factors for funding and executing a successful migration. The geographic diversity of vendors, while beneficial for resilience, could also introduce additional complexity in managing contracts and support across different jurisdictions during a migration. The contradictory "Total Vendors: 0" data point, if taken literally, would imply no vendor lock-in, but this conflicts with other vendor data and the presence of 39 services. Therefore, the assessment assumes the existence of vendors for these services, contributing to potential migration complexity.
Compliance
4 in-scope frameworks identified; showing 3.
NIS2 (source) — Assessment Required
NIS2 applicability depends on the specific IT services provided and company size. The risk level is Medium because: (1) If applicable, NIS2 violations can result in fines up to €10 million or 2% of annual global turnover; (2) The company name suggests IT services which could fall under 'digital service providers' or 'ICT service management' categories; (3) Size thresholds (50+ employees or €10M+ turnover) are unknown; (4) NIS2 enforcement is still developing across EU member states, but Denmark is actively implementing the directive.
ISO 27001 (source) — Assessment Required
ISO 27001 is not legally mandated but is increasingly expected for IT companies. The risk level is Medium because: (1) While voluntary, lack of ISO 27001 can impact business opportunities and client confidence; (2) IT companies face increasing cybersecurity threats and client demands for certified security management; (3) Some clients and contracts may require ISO 27001 certification; (4) Implementation provides actual security benefits beyond compliance; (5) Certification costs and ongoing maintenance represent moderate business investment.
SOC 2 (source) — Assessment Required
SOC2 is not legally mandated but is often required by clients for IT service providers. The risk level is Medium because: (1) While not legally required, lack of SOC2 can result in loss of business opportunities and client trust; (2) IT companies often need SOC2 to demonstrate security controls to enterprise clients; (3) The competitive disadvantage of not having SOC2 can be significant in the IT services market; (4) Implementation costs and audit requirements represent moderate business impact.
Financials
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.