Rethink Cyber ApS
Denmark · owned by Independent (Denmark) · rethink-cyber.com · 8 vendors
Rethink Cyber ApS is a Danish cybersecurity advisory firm that provides tailored consulting services within cyber and information security, helping organisations rethink their security approach strategically, effectively, and uncompromisingly. The company serves critical sectors including finance, energy, healthcare, transport, telecommunications, and the public sector, with offices in Copenhagen (Frederiksberg) and Aarhus. Their work spans strategic cybersecurity, governance, risk management, security architecture, behavioural design, and crisis preparedness.
Resilience scores
- Digital Sovereignty: 13
- Digital Resilience: 5
- Financial Resilience: 4
Technology vendors
- Cloudflare, Inc. — Technology — United States
- Google LLC — Technology — United States
- Umami — United States
- and 5 more
Insights
Last updated 2026-09-13 · revision 2
8 direct vendors, 159 subvendors
Direct vendors by controlling owner country (sample)
- United States: 6
- France: 1
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- Canada: 4
- Ireland: 2
- Netherlands: 2
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Rethink Cyber ApS demonstrates high migration readiness. Its internal tech stack, primarily consisting of SaaS platforms like Webflow and Demio, means the company is already operating in a cloud-native environment for these functions, reducing the complexity and effort associated with migrating traditional on-premise infrastructure. A key strength is the company's deep expertise in regulatory frameworks such as NIS2, ISO 27001, and DORA, which are central to its product offerings. This knowledge base is highly beneficial for navigating and ensuring compliance during any migration process. The geographic diversity of its vendor HQs and owner countries (Denmark, United States, France, United Kingdom) for its 11 services could provide flexibility in vendor selection and reduce overall vendor concentration risk. However, reliance on specific SaaS platforms could introduce vendor lock-in if the company decides to move away from these particular solutions, potentially requiring significant re-platforming and data migration efforts. Financial stability data is missing, making it difficult to assess the company's capacity to fund a major migration project. Data residency requirements are not specified, which could become a factor in future migration planning. The vendor lock-in risk is unknown, as details on contract complexity and ease of switching providers are not available.
Compliance
4 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is not mandatory but highly recommended for cybersecurity consultancies. It demonstrates information security management capabilities and is often required by clients in critical sectors. The medium risk reflects competitive disadvantage and potential client requirements rather than regulatory penalties. Given their work with finance, energy, and healthcare sectors, ISO 27001 certification would be expected by many clients.
GDPR (source) — Assessment Required
GDPR applies with HIGH confidence as the company is headquartered in Denmark (EU member state) and processes personal data through contact forms, employee data, and client data. Non-compliance can result in fines up to 4% of annual turnover or €20M. As a cybersecurity consultancy handling sensitive client information, the risk of data breaches and regulatory scrutiny is elevated. The company's privacy policy shows basic GDPR awareness but lacks detailed compliance documentation.
Evidence: https://www.rethink-cyber.com/privatlivspolitik
SOC 2 (source) — Assessment Required
SOC2 is not mandatory but highly recommended for cybersecurity service providers. As a consultancy serving critical sectors and handling sensitive client data, SOC2 certification would demonstrate security controls and build client trust. The medium risk reflects competitive disadvantage and potential client requirements rather than regulatory penalties.
Financials
Three-year financials
- 2025: gross profit DKK -213K, equity DKK -196K
Financial Resilience Score: 4/10
Rethink Cyber ApS is a very young Danish boutique cybersecurity advisory firm, likely founded in 2024-2025, with no publicly retrievable financial data. As an ApS in Danish accounting class B/micro, disclosure is limited and at most one annual report may have been filed. The advisory/consulting business model is inherently low capital intensity with minimal working capital requirements, which supports resilience for boutique consultancies that can typically operate profitably from year one if utilization is healthy. The company targets attractive end-markets including critical infrastructure clients in finance, energy, healthcare, public sector, telecom, and transport. These segments benefit from strong regulatory tailwinds (NIS2, DORA, GDPR) driving steady cybersecurity budgets. The company's differentiated positioning around LEGO Serious Play, co-creation methodologies, and automation across GRC/IAM/ITSM/SecOps suggests an attempt to move up-market from commoditized compliance work. However, significant risks include very small early-stage scale with limited equity buffer, unproven multi-year track record, key-person dependency typical of boutique advisory firms, single-country exposure to Denmark, and intense competition from larger Nordic and global cyber-advisory firms like Deloitte, EY, PwC, KPMG, Devoteam, Netcompany, Dubex, and Improsec. Limited public disclosure itself is a risk factor for counterparties assessing credit. The score of 4 reflects the high uncertainty inherent in an early-stage boutique with no public financial track record, despite favorable market positioning.
Key strengths: Attractive end-market focus on critical infrastructure with regulatory tailwinds (NIS2, DORA, GDPR), Low capital intensity advisory/consulting business model, Differentiated positioning with proprietary methodologies, Two-office Danish footprint (Copenhagen + Aarhus), Strong demand drivers in cybersecurity sector
Risk factors: Very small/early-stage ApS with limited equity buffer, Unproven multi-year track record, Key-person dependency typical of boutique advisory firms, Single-country exposure to Denmark only, Intense competition from Big 4 and established Nordic cyber-advisory firms, Limited public financial disclosure as ApS class B/micro, Cash burn risk if utilization drops
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Risk management: 0%
- Behavioural design: 0%
- Cyber 360 Analysis: 0%
- Strategic cybersecurity: 0%
- Platform-driven cyber governance: 0%
- Preparedness & crisis management: 0%
- Security architecture & processes: 0%
- Building cyber function/department: 0%
Workforce by country
- Denmark: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.