Monoceros Security ApS
Denmark · owned by Silbasto Holding ApS (Denmark) · monoceros.dk · 9 vendors
Monoceros Security is a Danish cybersecurity consultancy that provides strategic cyber security services to C-level executives, boards of directors, and CISOs. The company offers services including security partnership, cyber due diligence for M&A transactions, crisis management planning, and board-level cybersecurity training. Its mission is to help organizations anticipate, endure, and recover from cyber threats, building long-term cyber resilience.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 4
- Financial Resilience: 5
Disruption prediction
Monoceros Security ApS has an estimated 17% probability of disruption in the next 6 months.
3 of Monoceros Security ApS's 9 vendors monitored for disruptions.
Technology vendors
- Fortinet, Inc. — Technology — United States
- Google LLC — Technology — United States
- Palo Alto Networks, Inc. — Technology — United States
- and 6 more
Insights
Last updated 2026-09-15 · revision 24
9 direct vendors, 151 subvendors
Direct vendors by controlling owner country (sample)
- United States: 6
- Moldova: 1
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- Brazil: 1
- Bulgaria: 1
- Australia: 2
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Monoceros Security ApS demonstrates a medium migration readiness score of 60. **Strengths:** * **Modern, Cloud-Oriented Tech Stack:** The internal tech stack, consisting of WordPress, Elementor, Microsoft 365, Microsoft Outlook, and Cloudflare, is largely cloud-based and uses widely adopted platforms. This avoids the complexities of migrating legacy, on-premise, or highly customized monolithic systems. SaaS solutions like Microsoft 365 are inherently more portable and require less infrastructure migration effort. * **Relatively Simple Infrastructure:** As a micro-enterprise, the company likely has a relatively simple IT infrastructure, which reduces the complexity and scope of any potential migration project. * **Clear Data Residency Guidelines:** The company has clear data residency requirements, primarily driven by GDPR, mandating storage within EU/EEA-based systems and use of EU-region cloud storage. While a constraint, this clarity helps define the scope and requirements for any migration, making planning more straightforward. **Weaknesses:** * **Limited Financial Resources:** As a small company with limited financial data (DKK 791K gross profit in 2025, revenue null), Monoceros Security ApS may have constrained financial resources to fund a significant migration project, especially if it involves substantial re-platforming or vendor changes. * **Regulatory Compliance Complexity:** While the tech stack is modern, the regulatory environment adds complexity. GDPR and the Danish Data Protection Act (both "Medium" risk, "Assessment Required") necessitate careful consideration of data processing agreements, data transfer mechanisms, and privacy policies during any migration. Ensuring continued compliance with EU/EEA data residency requirements, especially when using third-party cloud services, is a critical factor. * **Vendor Lock-in (Moderate):** Although the tech stack is modern, there is a moderate level of vendor lock-in with key providers like Microsoft (for Microsoft 365 and Outlook). While these are common platforms with established migration paths, moving away from them would still require effort and potential re-training, especially for a small team. The "Total Vendors: 0" data point is contradictory, but the implied reliance on a few major tech providers is clear. * **NIS2 Applicability Uncertainty:** The "Assessment Required" status for NIS2 (and its Danish transposition) means that if the "Security Partner" service is deemed a "managed security service," future migrations would need to strictly adhere to NIS2 security and resilience requirements, adding a layer of complexity and potential cost.
Compliance
7 in-scope frameworks identified; showing 3.
GDPR (source) — Partially Compliant
Monoceros Security ApS is established in Denmark, an EU member state, making GDPR directly applicable to all its data processing activities, including employee and customer data.
As a Danish company, non-compliance with GDPR could lead to significant fines and reputational damage. The risk is high due to the potential for handling sensitive client data, even if their website states minimal data collection.
Evidence: https://monoceros.dk/privacy-policy/, https://www.monoceros.com/privacy-notice, https://www.monoceros.tools/privacy/
NIS2 (source) — Assessment Required
As a provider of cybersecurity services in the EU, Monoceros Security ApS is likely to be considered an ICT service management provider, which falls under the scope of NIS2 if they meet the size thresholds.
Non-compliance for a cybersecurity firm advising on NIS2 could result in severe reputational damage and potential regulatory penalties. Given their client base, which likely includes essential and important entities, the risk is high.
Evidence: https://monoceros.dk/, https://monoceros.dk/services/board-of-directors-training/, https://advisera.com/articles/who-does-nis2-apply-to/
ISO 27001 (source) — Assessment Required
ISO 27001 is not a legal requirement but a best-practice framework. For a cybersecurity advisory firm, certification is a strong indicator of their own security posture and is often expected by clients, especially in the enterprise and financial sectors.
For a cybersecurity firm, not having an ISO 27001 certification can be a competitive disadvantage, as it is a widely recognized standard for information security management. The risk is primarily commercial rather than legal.
Evidence: https://monoceros.dk/services/
Financials
Three-year financials
- 2025: gross profit DKK 791K, EBIT DKK 369K, equity DKK 321K
Financial Resilience Score: 5/10
Monoceros Security ApS demonstrates unusual profitability for a first-year startup, posting positive EBIT of DKK 369K and net profit of DKK 281K over its inaugural ~11-month period ending 31 December 2025. Equity of DKK 321K sits well above the DKK 40,000 registered share capital, indicating retained earnings have stayed in the business. The focused, high-margin advisory model targeting C-level executives, boards, and CISOs benefits from regulatory tailwinds such as NIS2 compliance demand, and the founder Per Silberg Hansen has visible credibility in Danish cybersecurity circles. However, resilience is materially constrained by the company's micro scale and key-person dependency. With only 1 average FTE in FY 2025 and 2 registered headcount, the business is effectively an owner-operator consultancy tied to the founder. Equity of DKK 321K provides very limited buffer against a lost engagement or bad debt, revenue is not disclosed (Danish class B micro-entity reporting), financial statements are unaudited, and the parent Silbasto Holding ApS is a personal holding vehicle rather than an operating group offering financial support. On balance, the company is profitable and debt-light but structurally fragile.
Key strengths: Profitable from inception (EBIT DKK 369K, net profit DKK 281K in first ~11 months), Equity of DKK 321K comfortably above DKK 40K share capital, Focused high-margin C-level advisory niche, Founder credibility in Danish cybersecurity thought leadership, Regulatory tailwind from NIS2 compliance demand
Risk factors: Key-person dependency on founder (avg 1 FTE, 2 registered headcount), Extremely small absolute equity buffer (DKK 321K), Revenue not disclosed under Danish class B reporting, Client concentration risk with single-employee delivery capacity, Unaudited financial statements, Parent (Silbasto Holding ApS) is a personal holding vehicle, not an operating group
Revenue by geography
- Denmark: 100%
Workforce by country
- Denmark: 2
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.