RiskFinder ApS

Denmark · owned by Risk ApS (Denmark) · riskfinder.dk · 7 vendors

RiskFinder ApS is a Danish SaaS company that provides a preparedness and risk management platform designed to help organisations structure risk assessments, emergency plans, action cards, and exercises in one unified tool. The platform is primarily built for the energy sector and critical infrastructure operators, supporting compliance with Danish and EU regulations such as BEK 260, NIS2, CER, and DORA. The company combines its software with direct access to expert advisory services, drawing on 15+ years of practical business continuity management (BCM) experience.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-13 · revision 8

7 direct vendors, 161 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

RiskFinder ApS exhibits medium migration readiness (Score: 50). Opportunities: The company's adoption of a modern, cloud-native architecture, particularly the use of Cloudflare Workers for serverless computing, suggests a flexible and modular approach that generally facilitates migration. Challenges: A primary challenge is the significant vendor lock-in associated with Cloudflare. While Cloudflare provides robust services, migrating core functionalities built on Cloudflare Workers, CDN, and WAF to a different cloud provider would likely require substantial refactoring and development effort. Strict EU data residency requirements, driven by GDPR and customer expectations (especially from NIS2/CER-regulated entities), impose significant constraints on potential migration targets, mandating EU-only hosting for platform data and requiring careful management of cross-border transfers for US-based sub-processors like Resend and Cloudflare. The company's small size (3 employees) and 100% revenue concentration in Denmark imply limited financial and human resources to undertake a complex, large-scale migration without external funding or significant operational impact. Regulatory compliance gaps (GDPR, lack of security certifications) would also need to be addressed meticulously during any migration to ensure continued adherence and customer trust.

Compliance

7 in-scope frameworks identified; showing 3.

Danish Energiberedskabsloven — Assessment Required

The Danish Energy Emergency Preparedness Act (Lov nr. 258) and its implementing regulation BEK 260 impose mandatory emergency preparedness requirements on energy sector operators in Denmark — specifically electricity, district heating, and gas companies. RiskFinder ApS is a software vendor that helps these regulated entities comply with BEK 260, but is not itself an energy sector operator subject to the law. Risk is Low for RiskFinder as a vendor, but the company's entire business model is built around helping its customers comply with this regulation. No direct compliance obligation falls on RiskFinder ApS under this law.

Evidence: https://www.riskfinder.dk/bek260/, https://www.riskfinder.dk/energiberedskab/, https://www.riskfinder.dk/fjernvarme/, https://www.riskfinder.dk/el-distribution/

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for information security management systems (ISMS). For a SaaS company serving critical infrastructure operators — whose data includes emergency plans, risk assessments, and operational continuity information — ISO 27001 certification is highly relevant and increasingly expected. Risk is Medium because: (1) the company processes sensitive operational data for energy and water sector clients who are themselves subject to strict security requirements under NIS2 and Danish sector-specific regulations (BEK 260, Energiberedskabsloven); (2) no ISO 27001 certification has been publicly disclosed; (3) the company is at an early stage (startup, 20+ customers) where formal ISMS certification may not yet have been pursued; (4) absence of certification could become a procurement barrier with regulated-sector customers. The risk is not High because the company is small and the data processed, while sensitive, does not include personal health data or financial data.

Evidence: https://www.riskfinder.dk/security/, https://www.riskfinder.dk/om-os/

NIS2 (source) — Assessment Required

RiskFinder ApS is a technology/SaaS company providing business continuity management (BCM), risk assessment, and emergency preparedness software — primarily to critical infrastructure operators in Denmark (district heating, electricity distribution, water sector). As a software vendor and service provider to critical infrastructure entities, RiskFinder itself is NOT one of the regulated essential or important entities under NIS2 Annex I or II. NIS2 regulates the operators of critical infrastructure (e.g., energy companies, water utilities), not their software vendors per se. However, NIS2 does include 'digital providers' (cloud computing services, online marketplaces, online search engines) and 'ICT service management (B2B)' as Important Entities under Annex II. If RiskFinder's SaaS platform qualifies as a managed ICT service or digital service provider to NIS2-regulated entities, it could fall under NIS2 scope. The risk level is Low because: (1) RiskFinder appears to be a small company (20+ customers, single director, startup stage) likely below the 50-employee / €10M turnover threshold for NIS2; (2) it is a software tool provider, not a critical infrastructure operator itself; (3) even if in scope, the company actively markets NIS2 compliance tools, suggesting awareness. Risk would escalate if the company grows beyond NIS2 size thresholds or if Danish authorities classify BCM SaaS providers as ICT service managers under NIS2.

Evidence: https://www.riskfinder.dk/nis2/, https://www.riskfinder.dk/om-os/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.datatilsynet.dk/english

Financials

Three-year financials

Financial Resilience Score: 4/10

RiskFinder ApS is an early-stage Danish SaaS company (CVR 44911760) that appears to have been incorporated in 2023 or 2024. No filed financial figures (revenue, EBIT, equity) were retrievable from public Danish registries during the research session, which is typical for a micro-cap ApS that files abbreviated accounts under Regnskabsklasse B. As a very early-stage entity, the company likely has a small equity base and thin or negative operating results, with runway dependent on non-dilutive grant funding and founder capital rather than operating cash flow. On the positive side, RiskFinder benefits from non-dilutive backing via Innovationsfonden's InnoFounder programme, providing state-supported seed capital. The company is well-positioned against a strong regulatory tailwind from NIS2, CER, DORA, BEK 260, and the Danish Energy Emergency Act, which force critical-infrastructure operators to purchase exactly this kind of compliance tooling through 2025-2027. Founder domain expertise (15+ years at ROCKWOOL and Haldor Topsøe) reduces execution risk. However, significant risks remain: key-person concentration around the founder, a very narrow customer base of only 20+ companies, long procurement cycles in utilities, and competitive pressure from larger GRC/BCM platforms. The score of 4 reflects the combination of early-stage financial fragility offset partially by grant funding, regulatory tailwinds, and credible founder expertise.

Key strengths: Non-dilutive funding from Innovationsfonden's InnoFounder programme, Strong regulatory tailwind from NIS2, CER, DORA, BEK 260, and Danish Energy Emergency Act, Founder domain expertise from 15+ years at ROCKWOOL and Haldor Topsøe, Focused SaaS model with recurring revenue potential, Integrated platform addressing compliance-driven demand through 2025-2027

Risk factors: Early-stage / micro-cap financial fragility with likely thin or negative operating result, Key-person concentration around single named founder with no visible executive team, Customer concentration risk with only 20+ customers disclosed, Long procurement cycles in utilities, district heating, and water sectors, Competitive pressure from larger GRC/BCM platforms (RSA Archer, Origami Risk, LogicGate, Neupart), Runway dependent on grants and founder capital rather than operating cash flow, No publicly disclosed financial figures reducing transparency

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report