Secher Security ApS
Denmark · owned by MBS Intermediate Dutch Bidco B.V. (Netherlands) · www.sechersecurity.dk · 15 vendors
Secher Security ApS is a Danish IT security and networking company headquartered in Silkeborg, Denmark. The company specialises in simplifying and optimising complex IT infrastructures for medium and large Danish businesses with global locations, primarily through Managed SASE solutions built on the Cato Networks platform. It is Denmark's most experienced Cato Networks partner and has received the prestigious Børsen Gazelle award three years in a row (2023–2025).
Resilience scores
- Digital Sovereignty: 47
- Digital Resilience: 6
- Financial Resilience: 7
Disruption prediction
Secher Security ApS has an estimated 17% probability of disruption in the next 6 months.
5 of Secher Security ApS's 15 vendors monitored for disruptions.
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Kriesi — Technology — Austria
- Palo Alto Networks, Inc. — Technology — United States
- and 13 more
Insights
Last updated 2026-09-13 · revision 7
15 direct vendors, 189 subvendors
Direct vendors by controlling owner country (sample)
- Romania: 1
- United States: 6
- Austria: 1
Subvendors by controlling owner country (sample)
- Australia: 3
- India: 2
- Germany: 7
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Secher Security ApS exhibits a medium level of migration readiness. Their strengths lie in a largely modern and cloud-native internal tech stack, with extensive use of SaaS platforms and a cloud-based security management platform (Cato Networks). This indicates a general comfort and capability with cloud adoption and modern IT environments. They also demonstrate a strong understanding and active management of regulatory requirements (GDPR, NIS2) and data residency constraints, which is a crucial asset for navigating the complexities of migrating data and services while maintaining compliance. Their expertise in modern cloud security technologies (SASE, ZTNA, Cloud Security) further suggests an internal skill set aligned with cloud migration principles. However, significant challenges impact their migration readiness. The most prominent is the high vendor lock-in associated with Cato Networks, which is foundational to their core managed security services delivery. Migrating away from this critical platform would likely be a highly complex, costly, and time-consuming endeavor, representing a major impediment to any large-scale core service migration. The 'Unknown' vendor lock-in risk further complicates the assessment of their flexibility. Additionally, the absence of financial data (revenue, growth) makes it impossible to assess their capacity to fund a potentially large-scale migration effort, which can be a significant barrier.
Compliance
3 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
GDPR applies with HIGH confidence as Secher Security is located in Denmark (EU member state) and processes personal data including employee data, customer data, and website visitor data as confirmed in their privacy policy. Non-compliance risks include fines up to 4% of annual turnover or €20M, plus reputational damage. Given their B2B cybersecurity focus and AAA credit rating, they likely have compliance measures in place, but no specific audit evidence was found.
Evidence: https://www.sechersecurity.dk/persondatapolitik/
SOC 2 (source) — Assessment Required
SOC2 is highly relevant for cybersecurity service providers like Secher Security who manage client IT infrastructure and security. While not legally mandatory, SOC2 compliance is often required by enterprise clients for vendor risk management. The risk is moderate as lack of SOC2 could limit business opportunities with security-conscious clients, but won't result in regulatory fines.
ISO 27001 (source) — Assessment Required
ISO 27001 is highly relevant for cybersecurity companies like Secher Security. While not legally mandatory, it's often expected by enterprise clients as proof of information security management maturity. Risk is moderate as lack of certification could impact competitive positioning and client trust, but won't result in regulatory penalties.
Financials
Three-year financials
- 2025: gross profit DKK 6.20M, EBIT DKK 2.34M, equity DKK 1.38M
- 2024: gross profit DKK 6.38M, EBIT DKK 4.30M, equity DKK 2.50M
- 2023: gross profit DKK 5.79M, EBIT DKK 3.71M, equity DKK 3.00M
Financial Resilience Score: 7/10
Secher Security ApS demonstrates strong qualitative financial resilience despite the absence of disclosed quantitative figures. The company has received the Børsen Gazelle award in three consecutive years (2023, 2024, 2025), which by definition requires at least a doubling of revenue or gross profit over a rolling four-year window, positive growth in each year, profitability throughout, and positive equity. This is an unusually strong track record for a Danish SME and signals sustained, profitable growth. The business model adds further resilience: Managed SASE and managed cybersecurity services typically generate recurring subscription revenue with multi-year contracts, providing strong revenue visibility. The company occupies a defensible niche as Denmark's most experienced Cato Networks partner, with high customer switching costs once SASE platforms are deployed. Reference customers include established mid-market Danish firms (Hoyer Motors, Flügger, Cabinplant), suggesting a stable enterprise contract base. However, several risks temper the score. The company is a small ApS with a limited capital base, heavy single-vendor dependency on Cato Networks, key-person risk around the founder, and likely customer concentration given the small employee base. FX exposure between USD-denominated Cato licences and DKK customer billing is also a structural risk. Without access to the official årsrapport, exact margins, equity, and liquidity cannot be confirmed.
Key strengths: Three consecutive Børsen Gazelle awards (2023, 2024, 2025) implying doubled revenue/gross profit and continuous profitability, Recurring-revenue managed services model with multi-year SASE subscription contracts, Specialised defensible niche as Denmark's most experienced Cato Networks partner, Blue-chip mid-market reference customers (Hoyer Motors, Flügger, Cabinplant), Structurally growing cybersecurity/SASE market in the Nordic mid-market, Active hiring and continued investment signals through 2025
Risk factors: Heavy dependence on single technology vendor (Cato Networks), Small ApS with limited capital base, Key-person risk around founder Kristian Secher-Johnsen, Skilled cybersecurity labour scarcity and wage inflation in Denmark, Likely customer concentration given small employee base, FX risk between USD-denominated Cato licences and DKK/EUR customer revenue
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Global Connectivity (GNX): 0%
- Managed SASE / Cato Networks platform: 0%
- Advisory / Proof-of-Concept / Risk Assessments: 0%
Workforce by country
- Denmark: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.