LCG

Sweden · lcg.nu · 1 vendor

LCG is a Danish cybersecurity company offering services such as offensive security, penetration testing, risk advisory, endpoint security, detection and response, and vulnerability management. They provide consulting, incident response, and managed security services to help clients address complex challenges and stay ahead of threats.

Resilience scores

Technology vendors

Insights

Last updated 2026-04-13 · revision 2

1 direct vendor, 59 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

LCG's migration readiness is significantly hampered by a lack of crucial information and implied vendor lock-in. There is no data available on the internal tech stack (e.g., cloud-native vs. legacy, containerization, microservices), making it impossible to assess technical readiness for migration. Similarly, financial stability (ability to fund migration) and the regulatory environment are unknown. The vendor relationship data is contradictory, stating 'Total Vendors: 0' but also detailing 'Total Services: 1' and vendor geographic information. Interpreting this to mean there is at least one vendor for the single service, LCG faces a high risk of vendor lock-in due to this concentration. This would significantly complicate and potentially increase the cost of any migration effort. The lack of vendor geographic diversity (only the United States) could also add complexity to migration planning. On a potentially positive note, data residency requirements are 'Not specified,' which could simplify data migration if there are no strict constraints, but this remains an area of uncertainty. The overall lack of technical and financial visibility, combined with the implied vendor lock-in, points to low migration readiness.

Compliance

6 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is widely applicable across industries for information security management. While not legally mandated in most jurisdictions, it's often required by customers, partners, or industry standards. Risk is medium because lack of certification can impact business opportunities and customer trust, especially in B2B environments.

SOC 2 (source) — Assessment Required

SOC2 is critical for service organizations, especially cloud providers and SaaS companies. While not legally mandated, it's often contractually required by customers and essential for business relationships. Risk is medium because it's primarily a business risk rather than regulatory penalty risk, but can significantly impact customer acquisition and retention.

NIS2 (source) — Assessment Required

NIS2 applies to Essential and Important Entities in specific sectors within the EU. Risk level is medium because it only applies to specific industries and company sizes (50+ employees or €10M+ turnover). Without knowing LCG's industry, size, or EU operations, assessment is required. Non-compliance can result in significant fines and operational restrictions.

Financials

Three-year financials

Financial Resilience Score: null/10

Insufficient data was retrieved from the research attempt on LCG (lcg.nu). The report indicates that the website fetch and multiple search approaches failed to return usable financial content, and cached or archive versions were also unavailable. As a result, no financial statements, revenue figures, profitability metrics, or balance sheet data could be extracted to support a resilience assessment. Without access to audited financials, management commentary, or third-party disclosures, no meaningful scoring can be performed. A complete reassessment would be required once primary source documents or verified secondary data become accessible.

Risk factors: No financial data publicly accessible or retrievable from available sources, Website and cached versions returned no usable financial disclosures, Private company with limited public reporting obligations, Inability to verify revenue, profitability, or capital structure

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report