Itavis
Denmark · owned by ITAVIS HOLDING ApS (Denmark) · itavis.dk · 22 vendors
Itavis provides network and security solutions, including managed IT operations, cybersecurity, and hosting services. The company helps businesses streamline and secure their entire network, offering services such as SASE solutions, cloud, and digital workplaces with intelligent security.
Resilience scores
- Digital Sovereignty: 23
- Digital Resilience: 7
- Financial Resilience: 6
Technology vendors
- Broadcom Inc. — Technology — United States
- Splide.js — Technology — Japan
- Veeam Software Group GmbH — Technology — United States
- and 23 more
Insights
Last updated 2026-09-13 · revision 7
22 direct vendors, 336 subvendors
Direct vendors by controlling owner country (sample)
- Japan: 2
- United States: 11
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- France: 9
- Spain: 1
- Luxembourg: 2
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Itavis exhibits high migration readiness, primarily driven by its core business offerings and internal technological adoption. Their product portfolio includes extensive 'Digital Transformation' services, specifically mentioning 'cloud migration (lift-and-shift, replatforming, refactoring)' and 'hybrid cloud orchestration.' This indicates deep expertise and practical experience in migrating complex IT environments. Internally, Itavis utilizes major cloud platforms such as Azure and AWS, alongside modern network solutions like Cato Networks, demonstrating a strong existing cloud footprint and familiarity with cloud-native principles. Their 'Managed IT Operations' service also covers hybrid environments (on-premise, cloud, Azure, AWS), further solidifying their capability to manage diverse infrastructure during migration. While regulatory requirements like GDPR and NIS2, along with data residency constraints, add complexity to migration planning, Itavis's expertise as an EU-based IT service provider suggests they are well-equipped to navigate these challenges for themselves, as they do for their clients. The internal tech stack comprises widely adopted platforms, which generally reduces severe vendor lock-in risks compared to highly specialized or proprietary systems. However, the assessment is limited by the absence of financial stability data, which would typically inform the company's capacity to fund large-scale migration initiatives. Additionally, specific vendor lock-in risks remain 'Unknown' based on the provided data.
Compliance
7 in-scope frameworks identified; showing 3.
ISAE 3000 (source) — Assessment Required
ISAE 3000 risk is MEDIUM for Itavis. ISAE 3000 (and its IT-specific variant ISAE 3402) is commonly used in Denmark and the Nordic region as an assurance framework for IT service providers and cloud/hosting companies. Danish enterprise clients and their auditors frequently require ISAE 3402 (or ISAE 3000) reports from IT service providers to satisfy their own financial audit requirements. As a provider of cloud hosting (IaaS), Managed IT-drift, and Backup & BCDR services, Itavis's clients may require ISAE 3402 Type II reports to demonstrate controls over financial reporting systems. The absence of a disclosed ISAE report is a gap in the Danish market context. Risk is MEDIUM because this is not a legal mandate but a strong market expectation in the Danish enterprise IT services sector.
Evidence: https://itavis.dk/managed-it-drift, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised-assurance-engagements-other-audits, https://fsr.dk/faglige-informationer/revision/isae-3402/
Danish Data Protection Act — Assessment Required
The Danish Data Protection Act (Act No. 502 of 23 May 2018, as amended) supplements GDPR with Denmark-specific provisions. Risk is HIGH because: (1) it applies to all Danish companies processing personal data; (2) it includes stricter rules for certain categories (e.g., CPR numbers — Danish civil registration numbers — which are subject to special restrictions); (3) Datatilsynet (the Danish DPA) actively enforces both GDPR and the national act; (4) Itavis, as an IT services provider, may process CPR numbers on behalf of clients in sectors like healthcare (KIAP medical practice referenced as client) and legal services (Kromann Reumert law firm referenced as client). The same gaps identified in the GDPR assessment apply here.
Evidence: https://itavis.dk/privatlivspolitik, https://www.datatilsynet.dk/english, https://www.retsinformation.dk/eli/lta/2018/502
GDPR (source) — Partially Compliant
GDPR is universally applicable to Itavis as a Danish-registered company (Itavis ApS) headquartered in Klampenborg, Denmark — an EU member state. Itavis processes personal data in multiple capacities: (1) as a data controller for its own website visitors, marketing contacts, and employees; (2) as a data processor for its managed IT, Managed SOC, cloud hosting, and SASE clients, handling potentially sensitive client network traffic and endpoint data. The risk level is HIGH because: (a) Itavis operates a 24/7 Managed SOC and Endpoint Detection & Response service, meaning it processes client network traffic and potentially sensitive personal data at scale; (b) the published Privacy Policy (effective 25-09-2024) lacks several GDPR-required elements — no Data Protection Officer (DPO) is named, no legal basis for each processing activity is specified, no data retention periods are stated, no mention of the right to lodge a complaint with Datatilsynet (the Danish DPA), and no reference to data transfer mechanisms for international transfers (e.g., via Cato Networks' global PoPs); (c) enforcement by Datatilsynet is active in Denmark; (d) fines can reach €20M or 4% of global annual turnover. The gap between the policy's stated commitments and GDPR's full requirements elevates risk.
Evidence: https://itavis.dk/privatlivspolitik, https://itavis.dk/esg, https://www.datatilsynet.dk/english, https://gdpr-info.eu/art-4-gdpr/
Financials
Three-year financials
- 2025: gross profit DKK 11.9M, EBIT DKK 704K, equity DKK 2.68M
- 2024: gross profit DKK 12.0M, EBIT DKK 933K, equity DKK 2.25M
- 2023: gross profit DKK 12.9M, EBIT DKK 355K, equity DKK 4.66M
Financial Resilience Score: 6/10
Itavis ApS is a long-established Danish managed IT-security and SASE specialist, operating continuously since 2001. Over two decades of sustained operations in Denmark's competitive IT services market indicates a durable, going-concern business with established customer relationships. The company benefits from a recurring revenue model through managed SASE, managed SOC (24/7), managed IT operations, and hosting/IaaS subscriptions, which typically support gross margin stability. Its enterprise/blue-chip customer base including Carlsberg (global SASE roll-out), ISS, Kromann Reumert, DBU, Taxa 4x35, Dansk Retursystem, and Danner suggests meaningful multi-year contract sizes with revenue visibility. However, as a small private ApS, Itavis has a limited capital base compared with larger A/S competitors like NNIT, Netcompany, or Nordics-wide MSPs. The business faces vendor concentration risk through heavy reliance on Cato Networks and Cisco Meraki technology stacks, exposing it to vendor pricing, licensing, and product roadmap risk. Customer concentration is also a concern, as a handful of large named enterprise clients likely generate a disproportionate share of revenue. Additionally, the talent-intensive nature of Danish IT security, with high and rising wages, creates structural margin pressure from SOC/24-7 staffing. Regulatory tailwinds from NIS2 compliance (effective late 2024) should support demand, but competition from Dubex, Improsec, Globeteam, Netic, IT Relation, and Conscia remains intense. Specific financial figures were not accessible in the source report.
Key strengths: Long operating history since 2001 (>20 years), Enterprise/blue-chip customer base including Carlsberg, ISS, Kromann Reumert, DBU, Recurring revenue model from managed services and subscriptions, Strategic partnership with Cato Networks positioning in fast-growing SASE segment, Regulatory tailwinds from NIS2 compliance in Denmark/EU
Risk factors: Small private ApS with limited capital base vs. larger competitors, Vendor concentration risk with heavy reliance on Cato Networks and Cisco Meraki, Customer concentration risk from handful of large enterprise clients, Talent-intensive business with high and rising Danish IT security wages, Highly competitive Danish managed-security market
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Managed SASE: 0%
- Managed IT Operations: 0%
- Digital Transformation: 0%
- Cybersecurity (Managed SOC, EDR, PAM, Backup/BCDR): 0%
Workforce by country
- Denmark: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.