Netspecialisten

netspecialisten.dk · 9 vendors

Resilience scores

Technology vendors

Insights

Last updated 2026-09-08 · revision 2

9 direct vendors, 150 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Netspecialisten exhibits very high migration readiness, largely driven by the reported 'Total Vendors: 0'. This indicates virtually no vendor lock-in for their own operations, providing exceptional flexibility to adopt new platforms and services without the complexities of existing vendor contracts or technology dependencies. Their proficiency in NIS2 compliance is a significant asset, ensuring they can effectively manage the regulatory and security aspects inherent in any migration project. Furthermore, their deep understanding of diverse modern network technologies (e.g., SD-WAN, Fortinet, Cisco) and mention of Azure security integrations suggests a strong capability to embrace contemporary IT infrastructure, including cloud-native or modernized environments. The primary potential challenge lies in their internal tech stack, which includes WordPress for their website. While not necessarily indicative of their core operational systems, it suggests that some internal applications might not be inherently cloud-native, containerized, or microservices-based, potentially requiring refactoring during a migration. The assessment is also limited by the absence of data on financial stability (ability to fund migration) and specific data residency requirements, which could introduce unforeseen complexities.

Compliance

7 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

Netspecialisten ApS is headquartered in Denmark, an EU member state, making GDPR universally applicable with no exceptions. As an IT/network consultancy and managed services provider, the company processes personal data across multiple categories: (1) employee/contractor personal data (HR records, payroll, access credentials), (2) customer contact and business data, (3) potentially sensitive client network data and logs that may contain personal information (IP addresses, user activity logs, authentication records), and (4) supplier/vendor data. The company explicitly offers 'log collection' and '24/7 network monitoring' services, which by their nature involve processing network traffic data that can constitute personal data under GDPR. As a managed services provider with access to client infrastructure, Netspecialisten likely acts as both a Data Controller (for its own employee/customer data) and a Data Processor (for client data processed on behalf of clients). Non-compliance risk is High due to: (a) the sensitive nature of network/security data processed, (b) the dual controller/processor role, (c) GDPR fines up to €20M or 4% of global annual turnover, (d) the Danish Data Protection Authority (Datatilsynet) is an active enforcement body with a track record of investigations and fines in Denmark, and (e) no public evidence of a formal GDPR compliance program or DPO appointment was found.

Evidence: https://netspecialisten.dk, https://netspecialisten.dk/om-os/hvem-er-vi/, https://netspecialisten.dk/log-collection/, https://netspecialisten.dk/network-operation-center/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679, https://www.datatilsynet.dk/english

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework developed by the AICPA, primarily relevant for technology and cloud service providers that store, process, or transmit customer data. Netspecialisten provides managed network services, 24/7 NOC/SOC monitoring, log collection, and patch management — all services where clients entrust their infrastructure and potentially sensitive data to Netspecialisten. Enterprise and multinational clients (which Netspecialisten explicitly states it serves) increasingly require SOC 2 Type II reports from their managed service providers as part of vendor due diligence. Risk is Medium because: (a) without a SOC 2 report, Netspecialisten may face competitive disadvantage or be excluded from enterprise procurement processes, (b) the absence of a SOC 2 report does not constitute non-compliance per se (it is voluntary), but it represents a trust and assurance gap, (c) clients subject to their own compliance requirements (NIS2, GDPR, ISO 27001) will scrutinize their MSP's security posture.

Evidence: https://netspecialisten.dk/network-operation-center/, https://netspecialisten.dk/log-collection/, https://www.aicpa-cima.com/resources/landing/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy

NIS2 (source) — Assessment Required

NIS2 applicability to Netspecialisten ApS has two distinct dimensions: (1) AS A SUBJECT ENTITY: Netspecialisten may itself fall under NIS2 as a provider of 'managed security services' or 'ICT service management' — categories explicitly listed under NIS2 Annex I (Essential Entities) and Annex II (Important Entities). Specifically, 'managed service providers' (MSPs) and 'managed security service providers' (MSSPs) are covered under NIS2 Article 3 and Annex I. The company provides 24/7 NOC/SOC services, network monitoring, patch management, and cybersecurity services — all hallmarks of an MSSP. However, the size threshold (50+ employees OR €10M+ turnover) is uncertain for this company, which appears to be a small-to-medium consultancy. (2) AS A SERVICE PROVIDER TO NIS2-COVERED ENTITIES: Netspecialisten explicitly markets NIS2 compliance services to its clients, indicating it serves entities that ARE subject to NIS2. This creates supply chain security obligations for Netspecialisten under its clients' NIS2 compliance programs. Risk is Medium rather than High because: (a) the company's size relative to the 50-employee/€10M threshold is unconfirmed, (b) if below threshold, NIS2 may not directly apply to Netspecialisten itself as a subject entity, though supply chain obligations from clients remain relevant. Fines under NIS2 can reach €10M or 2% of global turnover for Important Entities.

Evidence: https://netspecialisten.dk/nis2/, https://netspecialisten.dk/network-operation-center/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.cfcs.dk/en/, https://www.ft.dk/samling/20231/lovforslag/l111/index.htm

Financials

Three-year financials

Financial Resilience Score: 5/10

Netspecialisten ApS is a young Danish private limited company (founded around 2019-2020) operating in the network and cybersecurity services niche. The company benefits from structural tailwinds tied to the EU NIS2 directive (effective October 2024), which is driving demand for network security, OT security, and compliance advisory services in Denmark. Its certified Fortinet partner status provides credentialed vendor access and preferential pricing, while recurring-revenue services (24/7 NOC monitoring, patch management, service agreements) provide some earnings visibility. The Herning (Jutland) location offers a lower cost base than Copenhagen competitors. However, as a small Class B ApS with only 5-6 years of trading history, the company faces meaningful resilience risks: small scale increases key-person and customer concentration risk, heavy reliance on Fortinet's ecosystem creates vendor dependency, and competition for scarce Danish network/security engineering talent is a persistent margin pressure. Project-based revenue is discretionary and cyclical. Without access to audited årsrapport figures from datacvr.virk.dk, a precise resilience score cannot be firmly established, but the qualitative profile suggests a mid-range score reflecting balanced strengths and small-company risks.

Key strengths: Structural demand tailwind from EU NIS2 directive (effective October 2024), Certified Fortinet partner with credentialed vendor access, Recurring-revenue services (24/7 NOC, patch management, monitoring), Lower cost base in Herning vs. Copenhagen competitors, Niche positioning in network security and OT security

Risk factors: Small scale and key-person dependency as a young ApS, Heavy vendor dependency on Fortinet ecosystem, Wage inflation and talent scarcity for Danish network/security engineers, Cyclicality of project-based (non-managed-services) revenue, Limited financial disclosure as a Class B private company, Potential customer concentration risk given small size

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report