Security Tech Space
Denmark · owned by Independent (Denmark) · securitytechspace.dk · 5 vendors
Security Tech Space is a Danish national strategic cybersecurity initiative and knowledge centre based in Aarhus, founded by Alexandra Instituttet, INCUBA, Via University College, Aarhus Municipality, and Aarhus University. It operates a consortium of approximately 80 organisations and companies with the goal of strengthening Denmark's digital defence through research, innovation, talent development, and business collaboration. Its focus areas include an innovation lab for cybersecurity startups, matchmaking between students and companies, and knowledge/advisory services including a municipal cybershield and SMV:CERT.
Resilience scores
- Digital Sovereignty: 40
- Digital Resilience: 4
- Financial Resilience: 6
Disruption prediction
Security Tech Space has an estimated 17% probability of disruption in the next 6 months.
2 of Security Tech Space's 5 vendors monitored for disruptions.
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Elementor Ltd. — Technology — Israel
- Simply.com A/S — Technology — Denmark
- and 2 more
Insights
Last updated 2026-09-14 · revision 7
5 direct vendors, 126 subvendors
Direct vendors by controlling owner country (sample)
- Belgium: 1
- Israel: 1
- United States: 2
Subvendors by controlling owner country (sample)
- Denmark: 2
- Sweden: 2
- Poland: 3
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Security Tech Space demonstrates medium migration readiness. The most significant advantage is the reported 'Total Vendors: 0', which means there is no existing vendor lock-in, complex vendor contracts, or intricate integrations to untangle, greatly simplifying any potential migration effort. The internal tech stack, consisting of WordPress and Elementor, while not cloud-native, is relatively simple and widely supported, making a lift-and-shift or re-platforming to a cloud environment potentially straightforward compared to complex legacy systems. However, several factors present challenges. The regulatory environment, particularly GDPR and NIS2, imposes stringent data residency requirements and compliance obligations that will add complexity, cost, and meticulous planning to any cloud migration. The absence of revenue data also leaves the financial capacity to fund a significant migration project unknown. The current tech stack is not designed for cloud-native benefits like containerization or microservices, meaning a migration would likely involve re-platforming to fully leverage cloud advantages.
Compliance
6 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
Security Tech Space is established in Denmark, an EU member state. Therefore, it is subject to the General Data Protection Regulation regarding the processing of personal data.
As a Danish entity, non-compliance with GDPR could lead to significant fines and reputational damage. The consortium likely handles personal data of its members, employees, and event attendees, making data protection a critical obligation.
Danish DNS — Assessment Required
Applicability depends on whether the consortium operates online platforms that fall under the definition of intermediary services. Given its collaborative nature, it might host forums or other platforms for its members.
Non-compliance with national digital services legislation could lead to penalties. The risk is medium as the consortium likely operates online platforms for communication and collaboration among its members.
Evidence: https://sts.ly/ar/products/, https://en.digst.dk/about-us/organisation/division-for-digital-regulation-and-supervision/, https://en.digst.dk/digital-governance/nis-2/are-you-covered-by-the-danish-nis-2-law/
DORA (source) — Assessment Required
It is unlikely that the Digital Operational Resilience Act applies directly, as the consortium is not a financial entity. However, if it provides critical ICT services to financial entities within its consortium, it could be indirectly impacted.
The risk is low as it is unlikely that Security Tech Space is a direct financial entity or a critical ICT third-party provider to the financial sector. However, some of its consortium members may be.
Evidence: https://learn.microsoft.com/en-us/compliance/dora/dora-what-is-dora, https://www.dlapiper.com/en-us/insights/publications/2024/07/dora-when-regulated-entities-additionally-qualify-as-ict-third-party-service-providers, https://www.morganlewis.com/blogs/sourcingatmorganlewis/2025/01/dora-european-commission-clarifies-scope-of-ict-services, https://advisera.com/articles/dora-compliance-it-service-providers/, https://sts.ly/ar/products/, https://www.glocertinternational.com/resources/guides/dora-applicability-and-in-scope-entities/
Financials
Three-year financials
- 2025:
- 2024:
- 2023:
Financial Resilience Score: 6/10
Security Tech Space is a Danish Forening (association/non-profit) established on 29 August 2023, not a commercial vendor. As a result, no annual financial statements are publicly available on CVR/Virk, Proff.dk or ErhvervPlus, and traditional financial resilience metrics (revenue, EBIT, equity) cannot be assessed. The organisation's financial sustainability instead rests on grant funding, in-kind partner contributions and public-sector support. On the strength side, the consortium has a diversified and credible funding base: a DKK 4.8M cash grant from Salling Fondene, approximately DKK 33.5M in donated services from ~23 Danish cybersecurity companies, plus operational support from Aarhus Municipality, Industriens Fond, Aarhus University, the Alexandra Institute and INCUBA A/S. Membership has more than doubled from 35 to 80+ partner organisations, and governance has been strengthened by the appointment of Jakob Ellemann-Jensen as chairperson in May 2026. On the risk side, the entity is highly dependent on continued renewal of grants and in-kind contributions, has no independent commercial revenue stream, is very young (less than 3 years old), and outsources critical finance/communications functions to the Alexandra Institute. The absence of any public financial disclosure prevents external verification of liquidity, solvency or cost structure, which caps confidence in the resilience assessment.
Key strengths: Diversified funding base across municipal, foundation and industry sources, DKK 4.8M grant from Salling Fondene, DKK 33.5M in donated services from ~23 Danish cybersecurity companies, Institutional backing from Aarhus University, Alexandra Institute, INCUBA A/S and Aarhus Municipality, Broad consortium of 80+ partner organisations (grown from 35), High-profile governance under chair Jakob Ellemann-Jensen, Strategic tailwind from rising Danish focus on cyber and defence
Risk factors: Complete dependency on grants and in-kind donor contributions, No public financial disclosure — solvency and liquidity cannot be verified, Very young entity (established August 2023, limited track record), Not a revenue-generating business — cannot grow out of a funding shortfall, Finance and communications functions dependent on the Alexandra Institute, Vulnerability to non-renewal of municipal appropriations or foundation grants
Revenue by geography
- Denmark: 100%
Workforce by country
- Denmark: 9
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.