Ministeriet for Samfundssikkerhed og Beredskab

Denmark · owned by Independent (Denmark) · mssb.dk · 8 vendors

Ministeriet for Samfundssikkerhed og Beredskab (MSSB) is the Danish Ministry for Societal Security and Emergency Preparedness, responsible for preventing, withstanding, and managing major accidents, crises, disasters, and other events that challenge society's fundamental functions. It oversees two agencies — Styrelsen for Samfundssikkerhed (Agency for Societal Security) and Beredskabsstyrelsen (Danish Emergency Management Agency) — as well as two state-owned enterprises, Dansk Dekommissionering and DanPilot. The ministry sets cross-sectoral standards for resilience and emergency planning, and advises authorities, businesses, and the public.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-18 · revision 7

8 direct vendors, 146 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

MSSB's migration readiness is assessed as medium, leaning towards low, primarily due to significant technical, regulatory, and data residency constraints. The internal tech stack, featuring Umbraco CMS and WordPress for websites, is not inherently cloud-native or microservices-based, suggesting potential refactoring efforts for modernization. More critically, the 'Key Technologies' involve complex 'National Crisis Management Systems,' 'Emergency Communications Infrastructure,' and '112 Emergency Dispatch Systems,' which are typically monolithic and highly integrated, posing substantial challenges for migration to modern cloud architectures. There is no explicit mention of containerization or extensive cloud adoption. The regulatory environment is highly complex and evolving, with strict compliance requirements under GDPR, the Danish Data Protection Act, NIS2, the CER Directive, and the new EU Cyber Resilience Act. Maintaining meticulous compliance during any migration would require extensive planning and validation. Furthermore, MSSB is subject to extremely stringent data residency requirements, mandating primary data storage and long-term archival in Denmark, with classified data exclusively in secure Danish facilities, and sensitive cloud services expected to be EU/Danish-hosted. These requirements severely limit the choice of cloud providers and architectural flexibility. While the 'Total Vendors: 0' is listed, the 'Vendor Relationships' section indicates 'Total Services: 11' with vendors from 2 countries (Denmark, United States). The use of specific platforms (Umbraco, WordPress, HR Manager) and reliance on Statens IT as a central government IT provider suggests potential platform-specific and infrastructure-specific lock-in. The 'Unknown' vendor lock-in risk adds further uncertainty to migration planning. On the positive side, MSSB's 100% appropriation funding ensures financial stability, meaning that if a migration is deemed strategically necessary and approved, funding is likely to be available. However, the cumulative impact of technical complexity, stringent data residency, and a demanding regulatory landscape significantly lowers overall migration readiness.

Compliance

10 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is a voluntary information security standard. For a ministry responsible for societal security and cybersecurity coordination (NIS2), certification would be a highly relevant demonstration of best practice.

While not mandatory, the lack of an information security management system certification could indicate a lower maturity in security practices, which is a risk for a ministry dealing with national security.

GDPR (source) — Assessment Required

The General Data Protection Regulation, supplemented by the Danish Databeskyttelsesloven, applies to all organizations, including public authorities, that process the personal data of individuals within the EU.

As a public authority, the ministry processes personal data of employees and citizens. A data breach could lead to significant reputational damage and regulatory action from the Danish Data Protection Agency (Datatilsynet).

Evidence: https://www.hjulmandkaptain.dk/viden/mere-viden/forstaa-de-grundlaeggende-principper-i-gdpr/, https://www.datatilsynet.dk/regler-og-vejledning/gdpr-univers-for-smaa-virksomheder/grundlaeggende-om-gdpr, https://www.retsinformation.dk/eli/lta/2018/502, https://www.advokathuset.dk/erhvervsraadgivning/virksomhed/gdpr, https://www.scrive.com/da/ressourcer/trust-centre-eidas-standardising-digital-identity-in-the-eu, https://digst.dk/it-loesninger/eid-og-single-digital-gateway/eidas2-og-den-digitale-identitetstegnebog/

ISAE 3000 (source) — Assessment Required

ISAE 3000 is a standard for assurance engagements other than audits of historical financial information. It is not a legal requirement but could be used to provide assurance over non-financial information, such as cybersecurity controls.

This assurance standard is not typically required for a government ministry's core functions. The risk of not having one is low, as accountability is primarily managed through public law and governmental audit mechanisms.

Financials

Three-year financials

Financial Resilience Score: 9/10

As a Danish government ministry, MSSB is fully funded by parliamentary appropriations through the Finance Act (Finansloven), eliminating commercial revenue and credit risks entirely. It benefits from strong political prioritization, evidenced by the DKK 500 million annual allocation for 2026-2029 to strengthen societal resilience and the DKK 1.9 billion preparedness agreement covering 2025-2033. Total appropriations grew 16.7% to DKK 2,161.8M in FY2026, driven by new capital investments and the preparedness package. However, operational resilience is challenged by institutional immaturity - the ministry was only established in August 2024 and faced uncertainty about its survival under the new government. Rigsrevisionen (National Audit Office) has criticized IT security in two societally critical systems as 'very unsatisfactory,' citing outdated technology, missing security updates, and uncertainty about disaster recovery capability. Administrative errors have also occurred, including an erroneous aktstykke that required correction and formal apology to the Folketing's Finance Committee. Looking forward, out-year budgets (2027-2029) show a modest step-down after the 2026 peak due to one-off capex, and state-wide savings programs will trim appropriations by DKK 27.6M/year from 2030. Nonetheless, the ministry's core funding remains politically secured through multi-year agreements, making it financially highly resilient in the government-finance sense.

Key strengths: Fully funded by Danish state through parliamentary appropriation - no commercial revenue or credit risk, DKK 500M annual allocation for 2026-2029 to strengthen societal resilience, DKK 1.9B preparedness agreement covering 2025-2033, Total appropriations grew 16.7% in FY2026 to DKK 2,161.8M, Politically prioritized area with cross-party support, New SINE radio contract adds DKK 57.3M in 2026

Risk factors: Institutional immaturity - ministry only established August 2024, Rigsrevisionen criticized IT security in two critical systems as 'very unsatisfactory', Administrative errors requiring correction to Folketing's Finance Committee, Multi-year state savings program cuts rising to DKK 27.6M/year from 2030, Out-year budgets (2027-2029) show step-down after 2026 peak, Political uncertainty about ministry's continued existence under new governments

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report