Opiniosec
Denmark · owned by Independent (Denmark) · opiniosec.com · 11 vendors
Opiniosec is a Danish value-added reseller (VAR) of IT security and productivity software, founded in 2022. The company helps organizations strengthen their cybersecurity posture through automated penetration testing (NodeZero), NIS2 compliance, data security, and access management solutions. They serve 50+ customers across the Nordic region, including Danish municipalities, government agencies, and private enterprises.
Resilience scores
- Digital Sovereignty: 45
- Digital Resilience: 5
- Financial Resilience: 5
Disruption prediction
Opiniosec has an estimated 17% probability of disruption in the next 6 months.
3 of Opiniosec's 11 vendors monitored for disruptions.
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- jQuery Foundation — Technology — United States
- The Apache Software Foundation — Technology — United States
- and 17 more
Insights
Last updated 2026-09-13 · revision 13
11 direct vendors, 108 subvendors
Direct vendors by controlling owner country (sample)
- United States: 6
- Belgium: 2
- Denmark: 2
Subvendors by controlling owner country (sample)
- Singapore: 1
- Norway: 2
- Denmark: 4
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Opiniosec demonstrates medium migration readiness, balancing significant challenges with key opportunities. The primary challenges stem from their internal tech stack (WordPress, Kubio), which is not cloud-native, containerized, or microservices-based, implying a substantial re-platforming effort for a modern cloud migration rather than a simple lift-and-shift. The existing 'Assessment Required' status for critical regulations (GDPR, NIS2, SOC2, ISO 27001) means any migration would be complicated by the need to achieve compliance simultaneously, increasing scope, cost, and complexity. Strict GDPR data residency requirements for EU operations will further limit cloud provider choices and necessitate careful architectural planning. Additionally, the lack of publicly available financial stability data makes it difficult to assess their capacity to fund a substantial migration project. Conversely, a significant opportunity lies in Opiniosec's business model: they resell and implement advanced technologies like HashiCorp Terraform (Infrastructure as Code) and Vault (secrets management), as well as various XDR/SIEM and Zero Trust solutions. This indicates strong internal expertise and familiarity with modern, cloud-friendly infrastructure and security practices, which is a considerable asset for planning and executing a migration. While their internal stack is simple, it might not present complex vendor lock-in issues for the core platform itself, though specific hosting or plugins could introduce some. The diversity of their product vendors (5 HQ countries) also suggests experience in managing a varied technology ecosystem.
Compliance
4 in-scope frameworks identified; showing 3.
NIS2 (source) — Assessment Required
NIS2 applies to Essential and Important Entities in specific sectors. While Opiniosec is a cybersecurity company, they operate as a software reseller/consultant rather than a digital service provider or ICT service management company that would clearly fall under NIS2. However, given their role in critical cybersecurity infrastructure for Danish organizations and their mention of NIS2 compliance services, they may qualify as an Important Entity under digital providers or ICT service management. The medium risk reflects uncertainty about sector classification and the significant compliance burden NIS2 imposes, including incident reporting, risk management, and supply chain security requirements.
Evidence: https://opiniosec.com/
GDPR (source) — Assessment Required
As a Danish company in the EU, GDPR is mandatory and applies to all personal data processing including employee data, customer data, and supplier data. Non-compliance can result in fines up to 4% of annual turnover or €20M. Given their cybersecurity consulting business and customer base of 50+ organizations, they process significant amounts of personal data. The high risk is due to severe financial penalties, reputational damage in the cybersecurity industry, and potential business disruption. Their privacy policy shows basic GDPR awareness but lacks detailed compliance documentation.
Evidence: https://opiniosec.com/privatlivspolitik/
SOC 2 (source) — Assessment Required
SOC2 is not legally required but is a critical trust framework for cybersecurity service providers. Given Opiniosec's role as a cybersecurity consultant and reseller serving 50+ customers including government agencies, SOC2 certification would be highly valuable for customer trust and competitive positioning. The medium risk reflects that while not legally mandated, lack of SOC2 could impact business development, customer confidence, and competitive advantage in the cybersecurity market. Many enterprise customers expect SOC2 compliance from their cybersecurity vendors.
Financials
Three-year financials
- 2025: gross profit DKK 1.26M, EBIT DKK -2.27M, equity DKK -3.05M
- 2024: gross profit DKK 2.33M, EBIT DKK -945K, equity DKK -867K
- 2023: gross profit DKK 1.92M, EBIT DKK -187K, equity DKK -156K
Financial Resilience Score: 5/10
Opiniosec ApS operates in a structurally attractive and fast-growing Nordic cybersecurity market, benefiting from strong tailwinds including NIS2 directive compliance requirements, rising ransomware threats, and public-sector digitisation mandates. Its capital-light SaaS licence resale and advisory services model provides inherent revenue predictability through subscription-based recurring revenue streams, and its status as the #1 Horizon3.ai Gold Partner in the Nordics represents a genuine and defensible competitive differentiator for a company only three years old. However, the company is very early-stage, founded in 2022, with a customer base of only 50+ Danish organisations. This modest scale means the loss of even a small number of key accounts could have a material revenue impact. The portfolio, while diversified across 10+ vendors, is explicitly weighted toward NodeZero (Horizon3.ai) as the stated core product, creating meaningful vendor and revenue concentration risk. Additional vendor-side risks exist given that HashiCorp was acquired by IBM and Barracuda has undergone strategic shifts, illustrating how partner programme changes can disrupt a VAR's economics. The company competes in a highly competitive Danish VAR/MSSP market against significantly larger and better-resourced players such as Atea, Conscia, Logpoint, and Dubex. It also exhibits classic micro-enterprise risk characteristics: apparent key-person dependency on founder Kristoffer Waage Beck, a very small team estimated at fewer than 10 FTEs, and geographic concentration in Denmark with only aspirational Nordic expansion. No financial figures are publicly available, making it impossible to verify equity buffers, cash position, or profitability, which further limits confidence in resilience assessment. The score of 5 reflects a balanced view: the business model and market positioning are sound and above average for a company of this age, but the combination of early-stage scale, vendor concentration, limited customer base, key-person risk, and complete absence of verifiable financial data prevents a higher rating. The company has meaningful upside potential but carries commensurate early-stage financial risk.
Key strengths: Recurring SaaS subscription-based revenue model providing predictability, #1 Horizon3.ai Gold Partner in the Nordics — differentiated niche positioning, Strong market tailwinds from NIS2 directive compliance requirements across EU/Denmark, Diversified vendor portfolio of 10+ products across cybersecurity and productivity, Capital-light business model with minimal fixed asset requirements, Mixed public and private sector customer base (municipalities, corporates, associations), Active recruitment suggesting team and capability expansion underway
Risk factors: Very early-stage company (founded 2022, ~3 years old) with elevated cash burn and buffer risk, Heavy revenue concentration on NodeZero (Horizon3.ai) as stated core product, Small customer base of only 50+ Danish customers — high sensitivity to churn, Key-person dependency on founder Kristoffer Waage Beck, Vendor dependency risk — partner programme or pricing changes by third-party vendors could materially impact margins, HashiCorp acquired by IBM and Barracuda strategic shifts illustrate real vendor disruption risk, Geographic concentration in Denmark with no confirmed revenue outside Danish market, Competes against significantly larger players (Atea, Conscia, Logpoint, Dubex) with greater scale and resources, No publicly verifiable financial data — equity buffer, cash position, and profitability unknown, Estimated headcount below 10 FTEs limits operational resilience and delivery capacity
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.