Schmitto ApS

Denmark · owned by MO-GRUPPEN ApS (Denmark) · schmitto.dk · 15 vendors

Schmitto ApS is a Danish IT security consultancy run by Ole Schmitto, offering practical cybersecurity and GDPR advisory services to small and medium-sized enterprises (SMEs). The company helps businesses prioritize IT security strategies that maintain operational capability and flexibility, without relying on buzzwords or overly complex reports. Services include board-level risk advisory, fractional CISO engagements, GDPR compliance support, and acting as a bridge between business leadership and IT teams.

Resilience scores

Disruption prediction

Schmitto ApS has an estimated 17% probability of disruption in the next 6 months.

8 of Schmitto ApS's 15 vendors monitored for disruptions.

Technology vendors

Insights

Last updated 2026-09-13 · revision 26

15 direct vendors, 226 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Schmitto ApS exhibits medium migration readiness, reflecting a hybrid technology landscape and specific regulatory constraints. The company's internal tech stack includes a mix of traditional web technologies (WordPress, Apache) for its core website, alongside modern cloud-based services for operational functions (Microsoft 365, MailerLite, Backblaze, Plausible Analytics). While the use of open-source platforms like WordPress and Apache reduces proprietary vendor lock-in for the website, a full migration to a cloud-native, containerized, or microservices architecture would require significant modernization effort for this core component. Financial stability, implicitly limited as a sole-operator micro-enterprise with concentrated revenue, suggests that a large-scale, complex migration project might face budget and resource constraints. This would likely necessitate an incremental and cost-effective migration strategy. A critical factor influencing migration readiness is the company's "commendably EU-centric data residency posture." Any migration must meticulously maintain or enhance this, which could limit the choice of new providers or architectural designs, particularly if considering non-EU cloud providers. Furthermore, the "Partially Compliant" status for GDPR and the Danish Data Protection Act, along with the absence of ISO 27001 certification, represent compliance gaps that would need to be addressed during a migration, adding complexity and cost. On the positive side, the existing use of multiple cloud-based services demonstrates familiarity with cloud environments. The company's core business as a cybersecurity consultancy means it possesses strong internal expertise to manage a secure migration. The relatively small scale of operations (sole operator, limited number of tech stack components) also means that, despite the challenges, a migration is more manageable than for a large enterprise. Vendor lock-in is moderate due to the use of standard, widely adopted services, which generally have established migration paths.

Compliance

4 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is an internationally recognised information security management standard. While not legally mandatory, it is increasingly expected by enterprise clients of cybersecurity consultancies as evidence of the consultant's own security posture. Schmitto ApS is a micro-enterprise (1 person) for which formal ISO 27001 certification would be disproportionately burdensome and is not a regulatory requirement. However, as a cybersecurity consultant advising clients on security, there is a reputational and commercial expectation to demonstrate sound security practices. Risk is Low because: (1) ISO 27001 is voluntary, (2) the company's small size makes certification impractical, and (3) the founder's 40-year security background provides informal assurance. The 'Assessment Required' status reflects that the company's internal security practices are not publicly documented beyond the privacy policy.

Evidence: https://www.schmitto.dk/jeg-satte-mit-website-paa-slankekur-og-endte-med-a-i-sikkerhed/, https://www.schmitto.dk/privatlivspolitik/

GDPR (source) — Partially Compliant

GDPR is universally applicable to Schmitto ApS as a Danish (EU) company that actively processes personal data — including contact form submissions, newsletter subscriber data (name, email, consent timestamps), and email correspondence. The company has taken meaningful steps toward compliance: a published privacy policy (Privatlivspolitik) with legal bases cited under Article 6, documented data processors with GDPR-compliant contracts (Microsoft 365 EU/EEA, MailerLite Lithuania, Hetzner Germany, Backblaze EU), cookie-free analytics via Plausible, and documented data subject rights. Risk is rated Medium rather than Low because: (1) no formal DPO appointment is documented (though not legally required for a micro-enterprise of this size and processing nature), (2) no evidence of a formal Record of Processing Activities (RoPA) being publicly disclosed, (3) the company advises clients on GDPR but its own internal compliance posture beyond the privacy policy has not been independently audited, and (4) as a cybersecurity consultant handling client data, any breach could carry reputational and regulatory consequences. Risk is not High because the data processed is limited in volume and sensitivity (no special category data, no large-scale profiling), and the company demonstrates active GDPR awareness.

Evidence: https://www.schmitto.dk/privatlivspolitik/, https://www.schmitto.dk/, https://www.schmitto.dk/blog/

Danish Data Protection Act — Partially Compliant

The Danish Data Protection Act (Act No. 502 of 23 May 2018, as amended) supplements GDPR in Denmark with national specifications, including rules on processing of sensitive data, criminal records, CPR numbers (Danish personal identification numbers), and sector-specific provisions. As a Danish company processing personal data, Schmitto ApS is subject to this Act in addition to GDPR. Risk is Medium for the same reasons as GDPR — the company demonstrates awareness and basic compliance but lacks evidence of formal internal compliance documentation beyond the published privacy policy. The handling of CPR numbers (if any, e.g., in client engagements) would require specific safeguards under Section 11 of the Act.

Evidence: https://www.schmitto.dk/privatlivspolitik/, https://www.schmitto.dk/blog/

Financials

Three-year financials

Financial Resilience Score: 6/10

Schmitto ApS is a founder-led boutique cybersecurity advisory practice with a very low fixed cost base, no inventory, and no development staff. This structural simplicity gives it high resilience to operational shocks and technology cycle risks, particularly since the company is vendor-neutral and does not resell IT systems. Regulatory tailwinds from NIS2, DORA, and GDPR compliance requirements in Denmark support ongoing demand for exactly the type of advisory services the company offers. However, the business carries extreme key-person risk, as it depends entirely on founder Ole Schmitto. There is no scalability without hiring, revenue is capped by billable hours of one person, and client concentration risk is likely high given the small book. Given the founder began his career in 1987, the business also faces a limited succession horizon. On balance, financial resilience is moderate-to-good in the near term but structurally constrained over the long term. No actual financial figures (revenue, EBIT, equity) were retrievable in this session as the CVR/virk.dk register could not be accessed. As a small Danish ApS filing under regnskabsklasse B, the company typically discloses only bruttofortjeneste, profit/loss, equity, and total assets — revenue is generally not separately disclosed.

Key strengths: Very low fixed cost base with no inventory or development staff, Highly experienced founder with ~40 years in the field and two prior successful exits (Tempest to Nocom AB; eSec to Dubex), Vendor-neutral positioning insulates business from technology-cycle risk, Regulatory tailwind from NIS2, DORA, and GDPR compliance demands in Denmark

Risk factors: Extreme key-person risk — business depends entirely on Ole Schmitto, No scalability without hiring; revenue capped by billable hours of one person, Likely client concentration risk with a small retainer book, Limited succession horizon given founder's career start in 1987

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report