Moxso
Denmark · owned by Independent (Denmark) · moxso.com · 30 vendors
Moxso is a Danish cybersecurity company specializing in phishing simulations and dynamic security awareness training. Their platform delivers continuous phishing simulation campaigns combined with skill-based, individualized training to help organizations improve their cyber hygiene. The solution is designed to reduce human-related security risks by educating employees through targeted, adaptive learning experiences.
Resilience scores
- Digital Sovereignty: 17
- Digital Resilience: 4
- Financial Resilience: 5
Disruption prediction
Moxso has an estimated 11% probability of disruption in the next 6 months.
20 of Moxso's 30 vendors monitored for disruptions.
Technology vendors
- Anthropic, PBC — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Stripe, Inc. — Financial Services — United States
- and 31 more
Services catalogue
3 services in catalogue across 2 categories; runs on 30 sub-vendors.
- Awareness training
- Data breach detection
- Phishing simulation
Insights
Last updated 2026-09-13 · revision 31
30 direct vendors, 325 subvendors
Direct vendors by controlling owner country (sample)
- Australia: 1
- Canada: 2
- Netherlands: 1
Subvendors by controlling owner country (sample)
- Singapore: 1
- Denmark: 4
- Moldova: 1
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Moxso demonstrates a medium level of migration readiness, primarily supported by a modern tech stack and existing cloud infrastructure, but challenged by regulatory complexities and a significant dependency on its primary cloud provider. The company's 'Key Technologies' and 'Products Offered' indicate a focus on AI-based solutions, adaptive learning, and 'Europe-hosted cloud infrastructure,' suggesting a modern, likely cloud-native architecture that generally facilitates migration. Their current 'Europe-hosted cloud infrastructure' is well-aligned with GDPR data residency requirements for EU residents, which simplifies one aspect of a potential migration. Furthermore, the claim of 'GDPR-compliant data processing' and 'ISO 27001 certified security infrastructure' implies a foundational understanding and implementation of security and data governance, which are critical for a compliant migration. However, the regulatory environment presents significant challenges, with GDPR and NIS2 being mandatory or potentially applicable, requiring meticulous planning for data handling, incident reporting, and supply chain security during any migration. The 'Regulatory Environment' section also notes that SOC2 and ISO 27001 assessments are 'required,' indicating potential areas where further certification or verification may be needed, which could impact client trust during a migration. A major challenge for migration readiness is the significant dependency on a 'primary cloud service provider,' as highlighted by the October 2023 outage. This indicates a potential infrastructure vendor lock-in that could complicate and increase the cost of migrating core services. Similar to resilience, the 'Total Vendors: 0' data is contradictory; assuming the 'Internal Tech Stack' lists actual vendors, there is geographic diversity among these vendors, which generally reduces overall vendor lock-in. However, the 'Vendor Lock-in Risk: Unknown' for the broader vendor landscape remains a data gap. Crucially, the absence of data on revenue concentration and growth history makes it impossible to assess Moxso's financial capacity to fund a potentially complex and costly migration initiative.
Compliance
8 in-scope frameworks identified; showing 3.
GDPR (source) — Compliant
Moxso is headquartered in Denmark (EU), making GDPR universally applicable. The company explicitly acknowledges GDPR compliance on its homepage ('GDPR-compliant, Hosted in Europe') and in its privacy policy, which contains a dedicated GDPR section covering lawful bases, data subject rights, international transfer safeguards (SCCs), and data controller/processor roles. Risk is rated Medium rather than Low because: (1) Moxso processes employee behavioral data (click-through rates, training responses, breach monitoring data) on behalf of its customers, creating data processor obligations in addition to controller obligations; (2) the privacy policy was last updated in September 2021 and may not fully reflect subsequent GDPR enforcement guidance or the Schrems II landscape; (3) no formal DPO appointment is publicly disclosed; (4) sub-processors listed (AWS, DigitalOcean) require ongoing transfer impact assessments. Enforcement by Datatilsynet (Danish DPA) is active, and fines for non-compliance can reach €20M or 4% of global annual turnover.
Evidence: https://moxso.com, https://moxso.com/legal/privacy-policy, https://trust.moxso.com/, https://www.datatilsynet.dk/english, https://gdpr-info.eu/
Danish Data Protection Act — Compliant
The Danish Data Protection Act (Act No. 502 of 23 May 2018, as amended) supplements GDPR with national specifications, including stricter rules on processing sensitive personal data, employee monitoring, and specific derogations. As a Danish company, Moxso must comply with both GDPR and the Danish DPA. Risk is Medium because: (1) Moxso's phishing simulation service involves monitoring employee behavior (click rates, training responses), which may engage Danish rules on employee surveillance; (2) the Danish DPA has specific provisions on processing employee data that go beyond GDPR; (3) Datatilsynet actively enforces both GDPR and the Danish DPA. The privacy policy acknowledges GDPR compliance but does not specifically address Danish DPA nuances.
Evidence: https://moxso.com/legal/privacy-policy, https://www.datatilsynet.dk/english, https://www.retsinformation.dk/eli/lta/2018/502
ISO 27001 (source) — Compliant
Moxso explicitly displays an ISO 27001 certification badge on its homepage under 'Enterprise security – ISO 27001'. ISO 27001 is the international standard for information security management systems (ISMS). Risk is Low because: (1) the certification is publicly claimed and prominently displayed; (2) ISO 27001 certification requires third-party audit by an accredited certification body and annual surveillance audits; (3) as a cybersecurity company, maintaining ISO 27001 is both a market expectation and a strong indicator of mature security controls; (4) the Trust Center powered by Vanta supports ongoing compliance monitoring. The primary residual risk is that the specific certification body, certificate number, and expiry date are not publicly disclosed for independent verification.
Evidence: https://moxso.com, https://trust.moxso.com/, https://moxso.com/about
Financials
Three-year financials
- 2025: gross profit DKK -1.24M, EBIT DKK -20.6M, equity DKK 18.7M
- 2024: gross profit DKK 600K, EBIT DKK -5.77M, equity DKK 4.74M
- 2023: gross profit DKK 1.16M, EBIT DKK -784K, equity DKK -784K
Financial Resilience Score: 5/10
Moxso ApS is a young Copenhagen-based cybersecurity SaaS company (registered circa 2021 based on CVR numbering) operating in the human risk management space. The actual financial figures (revenue, EBIT, equity) could not be retrieved from Danish authoritative sources (CVR/virk.dk, Erhvervsstyrelsen) or aggregators (Proff.dk, Bizzy.dk) during the research session, so a precise resilience score cannot be anchored in filed accounts. As a small ApS, the company likely files abbreviated accounts under regnskabsklasse B, meaning revenue may not even be disclosed publicly—only gross profit (bruttofortjeneste). Qualitative strengths supporting resilience include a credible Danish enterprise customer base (Bygma, Movia, Seges, NRGi, Aarsleff, Ganni, Whiteaway Group, and others), ISO 27001 certification, EU/GDPR-compliant hosting, and a TDC 2025 cybersecurity award. These provide market credibility and suggest recurring SaaS revenue streams. However, as an early-stage company, Moxso likely has limited equity cushion and may still be investing ahead of revenue with potentially negative EBIT. Customer concentration in a single small market (Denmark) and heavy competition from larger vendors (KnowBe4, Hoxhunt, CultureAI, Cyberpilot, Proofpoint, Mimecast) create material risks. A mid-range score reflects the balance between credible traction signals and unverified financial position typical of a Series-seed/Series-A stage startup.
Key strengths: Credible Danish enterprise customer base (Bygma, Movia, Seges, NRGi, Aarsleff, Ganni, Whiteaway Group), ISO 27001 certification and EU/GDPR-compliant hosting, TDC 2025 cybersecurity award recognition, Product positioning aligned with growing SBCP (Security Behavior and Culture Programs) segment, SaaS subscription model providing recurring revenue predictability
Risk factors: Small, young ApS with likely limited equity cushion, Probable negative EBIT as an early-stage SaaS investing ahead of revenue, Customer concentration in Danish market exposes to single-market risk, Crowded competitive field with larger incumbents (KnowBe4, Hoxhunt, CultureAI, Cyberpilot, Proofpoint, Mimecast), Limited external financial visibility due to ApS abbreviated filing structure, Actual financial figures could not be verified from CVR filings
Revenue by geography
- Denmark: 100%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.