Abion AB (formerly Ports Group)
Sweden · owned by Bridgepoint (United Kingdom) · portsgroup.com · 23 vendors
Originally founded in 1994 as Ports Group, the company rebranded to Abion in 2023 after merging with BRANDIT. It provides full-circle intellectual property solutions including trademark protection, domain name management, web security, and online brand protection, serving clients globally from offices across Europe, Asia, the UAE, and Australasia.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Netlify, Inc. — Technology — United States
- The Apache Software Foundation — Technology — United States
- Veeam Software Group GmbH — Technology — United States
- and 20 more
Services catalogue
5 services in catalogue across 3 categories; runs on 23 sub-vendors.
- Report Design
- DNS Hosting
- DNS
Insights
Last updated 2026-07-30 · revision 2
23 direct vendors, 274 subvendors
Direct vendors by controlling owner country (sample)
- France: 2
- Denmark: 1
- Switzerland: 1
Subvendors by controlling owner country (sample)
- Belgium: 1
- Canada: 9
- Portugal: 1
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Abion AB shows moderate readiness for migration, primarily due to its existing experience with cloud and modern architectural elements. The "Abion Core" platform is described as "cloud-based," indicating prior engagement with cloud infrastructure. The company also offers "VPS solutions," suggesting familiarity with virtualized environments. The use of REST APIs and SAML/2FA in their internal tech stack points to modern integration capabilities and secure authentication, which are beneficial for migration efforts. However, several factors introduce significant challenges and uncertainties. The internal tech stack includes WordPress, which, depending on its implementation, could represent a more monolithic architecture that is complex to refactor for cloud-native or microservices environments. There is no explicit mention of containerization (e.g., Docker, Kubernetes) or a microservices architecture, suggesting a potentially less agile infrastructure. Crucially, data residency requirements are "Not specified," and the regulatory environment is "[]" (not provided); these unknowns can significantly complicate and constrain migration strategies, potentially requiring extensive compliance work. Financial stability data is also missing, making it impossible to assess the company's capacity to fund a potentially large-scale migration. The vendor relationship data is contradictory ("Total Vendors: 0" vs. "32 services, 7 countries"); if vendors are indeed involved in 32 services, the "Vendor Lock-in Risk: Unknown" is a significant concern, as high lock-in can severely impede migration flexibility and increase costs. Reliance on a specific partner like DigiCert for SSL infrastructure could also present a minor lock-in point.
Compliance
8 in-scope frameworks identified; showing 3.
ePrivacy Directive — Partially Compliant
Abion AB operates a website with multiple cookie categories including functional, analytical/performance, advertising/ad-tracking, ad measurement, and personalized ads cookies. The website implements a cookie consent banner with granular controls (necessary only vs. accept all), which is a positive compliance indicator. However, the use of advertising and personalized ad cookies — particularly involving third-party services like Google Tag Manager (GTM-K2T758H) — requires valid prior consent under the ePrivacy Directive as implemented in Swedish law (Lag om elektronisk kommunikation, LEK). Risk is Medium because: (1) The cookie banner exists but the default state and pre-ticking of non-essential cookies cannot be verified from the fetched content; (2) Google Tag Manager is loaded on the page, which may fire tags before consent is obtained depending on implementation; (3) Swedish IMY (Integritetsskyddsmyndigheten) has actively enforced cookie consent requirements against Swedish companies. Fines under LEK can reach SEK 5M or 1% of annual turnover.
Evidence: https://abion.com/privacy-policy/, https://abion.com/
ICANN Registrar Accreditation Agreement — Compliant
Abion AB is Sweden's first ICANN-accredited registrar (since 1999) and currently maintains active ICANN accreditation. ICANN compliance is a core operational requirement — loss of accreditation would terminate the company's ability to register generic top-level domain (gTLD) names. The company's long-standing accreditation (25+ years) and active operations as a registrar are strong indicators of ongoing compliance. Risk is Low because the company's core business depends on maintaining ICANN accreditation, creating strong incentive for compliance. The company has also announced plans to apply for the .abion gTLD, demonstrating continued active engagement with ICANN processes.
Evidence: https://abion.com/about-us/, https://abion.com/registrants-benefits-and-responsibilities/, https://whois.abion.com/
ISO 27001 (source) — Compliant
Abion AB achieved ISO 27001 certification in 2024, as explicitly stated on the company's About Us page and confirmed by the ISO 27001 certification badge displayed prominently in the website footer and About Us page. ISO 27001 certification requires a formal third-party audit by an accredited certification body, demonstrating that the company's Information Security Management System (ISMS) meets the international standard. This is the strongest available evidence of information security compliance. Risk is Low because the certification is current (2024), publicly disclosed, and represents a rigorous independent assessment. Ongoing risk relates to maintaining certification through surveillance audits (typically annual) and recertification (every 3 years).
Evidence: https://abion.com/about-us/, https://abion.com/privacy-policy/, https://abion.com/data-processing-addendum/
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 7/10
Abion AB (formerly Ports Group) demonstrates strong qualitative financial resilience despite lack of publicly disclosed figures in this session. The company benefits from recurring, subscription-like revenue streams from corporate domain portfolios, trademark renewals, and monitoring services, which typically feature high renewal rates and long-term B2B contracts with blue-chip enterprise clients including Spotify, Oatly, Lyko, and STIGA Sports. This creates a sticky, predictable revenue base that supports financial stability through economic cycles. The backing of Nordic Capital, a major Nordic private equity firm, since 2022 provides significant capital for M&A activity and international expansion, as evidenced by multiple bolt-on acquisitions in 2023-2024 across Turkey, Southern Europe, and MENA. Industry-recognized certifications (ISO 27001, ICANN accreditation, DigiCert Platinum Elite Partner) create meaningful barriers to entry. Geographic diversification across 14+ countries reduces single-market concentration risk. However, PE ownership typically brings elevated leverage from acquisition debt, creating interest cost sensitivity. Acquisitive growth strategies can mask organic growth trends and pose integration risks. Structural pricing pressures from ICANN/Verisign fee changes could compress margins if not passed through. FX exposure across SEK, EUR, USD, GBP, and CHF adds complexity. Overall, the recurring revenue model and strong customer base support a moderately strong resilience rating, though the leverage profile and inability to verify specific financials prevents a higher score.
Key strengths: Recurring subscription-like revenue with high renewal rates, Sticky enterprise customer base including Spotify, Oatly, Lyko, STIGA Sports, Nordic Capital private equity backing since 2022, ISO 27001, ICANN, and DigiCert Platinum Elite certifications, Geographic diversification across 14+ countries, Structural tailwinds from rising phishing/brand-abuse threats, Upcoming new gTLD program round in 2026 (.abion application)
Risk factors: Elevated leverage typical of PE-owned businesses, Integration risk from multiple bolt-on acquisitions, Registry/registrar pricing pressure from ICANN fee increases, FX exposure across SEK, EUR, USD, GBP, CHF, Competition from larger global peers (CSC, MarkMonitor/Clarivate, Com Laude, Safenames), Enterprise marketing/legal budget sensitivity for new-logo sales, Acquisitive growth may mask underlying organic growth trends
Revenue by geography
- Rest of Europe: 0%
- Asia-Pacific and MENA: 0%
- Nordics (Sweden, Norway, Denmark): 0%
Revenue by product/service
- Web Security: 0%
- Online Brand Protection: 0%
- Corporate Domain Management: 0%
- Legal Services / Trademarks: 0%
Workforce by country
- China: 0
- Italy: 0
- Malta: 0
- Spain: 0
- Norway: 0
- Sweden: 0
- Turkey: 0
- Denmark: 0
- Ireland: 0
- Malaysia: 0
- New Zealand: 0
- Switzerland: 0
- United Kingdom: 0
- United Arab Emirates: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.