Retest Security ApS

Denmark · owned by Independent (Denmark) · www.retest.dk · 11 vendors

Retest Security ApS is a Danish-owned IT security testing and analysis company specializing in vulnerability scanning, penetration testing, and security advisory services. The company offers a broad range of services including web application pentests, red team exercises, cloud security reviews, and DevSecOps consulting for organizations across all industries. Their approach is based on recognized standards such as OWASP, ISO 27XXX, PTES, and NIST, with a focus on independent and technically in-depth security assessments.

Resilience scores

Disruption prediction

Retest Security ApS has an estimated 17% probability of disruption in the next 6 months.

6 of Retest Security ApS's 11 vendors monitored for disruptions.

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 11 sub-vendors.

Insights

Last updated 2026-09-13 · revision 7

11 direct vendors, 194 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Retest Security ApS demonstrates medium migration readiness, scoring 65. A significant advantage for migration readiness is the explicit statement of 'Total Vendors: 0' in the provided data. If taken literally, this implies a complete absence of vendor lock-in, which is a major enabler for flexible migration strategies, as there are no external dependencies or complex vendor contracts to untangle. This significantly reduces the complexity and cost typically associated with vendor transitions during migration. However, several factors present challenges. Their internal tech stack, primarily WordPress, suggests a potentially monolithic architecture that is not inherently cloud-native, containerized, or microservices-based. Migrating such a system to a modern cloud environment would likely require substantial re-platforming or re-architecture efforts, increasing time and cost. Furthermore, as a Danish company operating in the EU, Retest Security is subject to strict GDPR data residency and transfer requirements. Any migration involving personal data would need meticulous planning to ensure continued compliance, potentially limiting choices for cloud regions or requiring robust data transfer safeguards, adding complexity. The lack of financial data (revenue concentration, growth history) also prevents an assessment of their capacity to fund a potentially significant migration project. While the vendor situation is a strong positive, the legacy tech stack and regulatory environment necessitate careful planning.

Compliance

3 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

GDPR carries severe financial penalties (up to 4% of annual turnover or €20M) and reputational damage for non-compliance. As a Danish company processing personal data of employees, customers, and website visitors, GDPR is mandatory. The high risk stems from the significant penalties, strict enforcement in Denmark, and the company's role as a data controller. Their privacy policy shows awareness but full compliance assessment would require detailed audit.

Evidence: https://retest.dk/privatlivspolitik/

SOC 2 (source) — Assessment Required

As a cybersecurity service provider handling customer data and providing cloud-based security services (ReScan X platform), SOC2 compliance would enhance customer trust and competitive positioning. Risk is medium as it's not legally mandatory but increasingly expected by enterprise customers for vendor assurance.

ISO 27001 (source) — Assessment Required

ISO 27001 is highly relevant for cybersecurity companies as it demonstrates information security management maturity. Risk is medium as it's not legally required but provides significant competitive advantage and customer confidence. Many enterprise customers expect security vendors to have ISO 27001 certification.

Financials

Three-year financials

Financial Resilience Score: 6/10

Retest Security ApS is a young Danish cybersecurity boutique (founded ~2019) operating in a sector with strong tailwinds from NIS2 regulatory implementation in Denmark and the EU. The company has developed a portfolio of subscription-based services (ReScan X, Ongoing Assume Breach, Ongoing Web Pentest) which provides some recurring revenue predictability and improves cash-flow stability compared to pure project-based consulting. Its specialist independent positioning, recognized affiliation with the Danish National Coordination Center for Cyber Security (NCC-DK), and a diverse mix of public sector and private commercial clients further strengthen its market standing. However, as a small private ApS, the company has a limited capital buffer and is vulnerable to key-person risk, particularly given the scarcity and cost of cybersecurity talent in Denmark. Geographic concentration is essentially 100% Denmark, exposing the firm to a single domestic economy. The Danish cybersecurity market is crowded with larger competitors (Dubex, Improsec, FortConsult/NCC Group, Truesec, Globeteam), and automation trends in PtaaS may compress margins on commodity scanning. Specific financial figures (revenue, EBIT, equity) could not be verified from primary sources in this session, limiting the precision of this resilience assessment.

Key strengths: NIS2 regulatory tailwinds driving mandatory pentest demand, Recurring subscription revenue model (ReScan X, Ongoing Assume Breach, Ongoing Web Pentest), Recognized affiliation with NCC-DK, Diverse client base across public sector (municipalities) and private commercial customers, Independent pure-play testing firm positioning (no reseller conflicts), Continued hiring and expanding service portfolio (LLM/AI Pentest, Threat Modelling)

Risk factors: Limited capital buffer typical of small ApS structures, Key-person/founder dependency on senior pentesters, Geographic concentration ~100% in Denmark, Crowded competitive landscape in Danish cybersecurity, Margin pressure from PtaaS automation on commodity scanning, Cybersecurity talent scarcity and cost in Denmark

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report