SektorCERT
Denmark · owned by Independent (Denmark) · sektorcert.dk · 31 vendors
SektorCERT is a non-profit cybersecurity center for critical sectors in Denmark. The organization monitors critical infrastructure through an extensive sensor network to detect cyber attacks and provides cybersecurity services, training, and threat intelligence to Danish companies in critical infrastructure sectors including energy, water, and district heating.
Resilience scores
- Digital Sovereignty: 19
- Digital Resilience: 5
- Financial Resilience: 8
Technology vendors
- Fortinet, Inc. — Technology — United States
- Netic A/S — Technology — Denmark
- Palo Alto Networks, Inc. — Technology — United States
- and 28 more
Insights
Last updated 2026-02-19 · revision 18
31 direct vendors, 319 subvendors
Direct vendors by controlling owner country (sample)
- Austria: 1
- Bangladesh: 1
- Australia: 2
Subvendors by controlling owner country (sample)
- Poland: 3
- Germany: 9
- Singapore: 1
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
SektorCERT exhibits medium migration readiness. A key strength is its strong financial stability, evidenced by consistent revenue growth, which provides the necessary resources to fund a migration initiative. The existing use of AWS EU (Frankfurt) for some services suggests prior experience with cloud environments, which can ease the transition to further cloud adoption. The internal tech stack, comprising Mattermost and WordPress, while not inherently cloud-native, offers flexibility in deployment options, potentially allowing for lift-and-shift or re-platforming strategies. However, several factors present significant challenges to migration readiness. The regulatory environment is complex and demanding, with GDPR and NIS2 both requiring assessment and carrying 'High' risk levels. Strict EU/EEA data residency requirements, explicitly mentioning Frankfurt for hosting and third-party processors, impose constraints on cloud provider and region selection, increasing complexity and potentially cost. The internal tech stack is not explicitly described as cloud-native, containerized, or microservices-based, indicating that a significant migration might require substantial refactoring efforts. The 'Unknown' vendor lock-in risk is a major concern, especially considering the mention of '105 services' and specific vendors like Splunk and Crowdstrike; migrating away from these established platforms could be complex, costly, and time-consuming. The sheer number of services (105) implies a potentially intricate web of vendor relationships and dependencies that would need careful management during any migration.
Compliance
4 in-scope frameworks identified; showing 3.
NIS2 (source) — Assessment Required
SektorCERT operates in Denmark (EU) serving critical infrastructure sectors (energy, district heating, water), likely qualifying them as an Essential or Important Entity under NIS2.
NIS2 likely applies with high confidence as SektorCERT operates in Denmark (EU) serving critical infrastructure sectors including energy, district heating, and water - all covered under NIS2 as Essential Entities. As a cybersecurity service provider to these sectors, they may qualify as Important Entity under digital service providers. Non-compliance risks include fines up to €10M or 2% of annual turnover, plus operational restrictions. The directive's focus on cybersecurity resilience directly impacts their operations.
Evidence: https://sektorcert.dk
GDPR (source) — Assessment Required
SektorCERT is headquartered in Denmark (EU) and processes extensive personal data, making GDPR mandatory.
GDPR applies with high certainty as SektorCERT is headquartered in Denmark (EU member state) and processes extensive personal data including employee data, member contact information, network monitoring data with IP addresses, and user data from their Mattermost platform. Non-compliance risks include fines up to 4% of annual turnover or €20M, plus reputational damage. Their privacy policy shows GDPR awareness but compliance status requires detailed assessment.
Evidence: https://sektorcert.dk/persondata/
SOC 2 (source) — Assessment Required
SOC2 may be relevant as SektorCERT provides cybersecurity services and operates cloud platforms to critical infrastructure clients, demonstrating security controls maturity.
SOC2 may be relevant as SektorCERT provides cybersecurity services including network monitoring, incident response, and cloud-based platforms (Mattermost) to critical infrastructure clients. While not mandatory, SOC2 compliance would demonstrate security controls maturity and may be expected by enterprise clients. Risk is moderate as it's primarily a competitive/trust factor rather than regulatory requirement.
Financials
Three-year financials
- 2022: revenue DKK 28,500,000, EBIT DKK 4,200,000, equity DKK 10,500,000
- 2021: revenue DKK 22,100,000, EBIT DKK 3,100,000, equity DKK 7,800,000
- 2020: revenue DKK 17,800,000, EBIT DKK 2,500,000, equity DKK 5,500,000
Financial Resilience Score: 8/10
SektorCERT demonstrates strong financial resilience based on the available data: * Consistent Revenue Growth: The company has shown robust year-over-year revenue growth, indicating strong market demand for its cybersecurity services. Growth rates of 24-29% are excellent for a specialized service provider. * Healthy Profitability: Operating income (Resultat før skat) has grown in line with, or even slightly faster than, revenue, suggesting efficient cost management and strong pricing power. The profit margins appear healthy for a service-based business. * Solid Equity Base: Equity has grown significantly, indicating that the company is retaining earnings and strengthening its balance sheet. A growing equity base provides a buffer against potential losses and supports future investments without heavy reliance on external debt. * Self-Funding Capacity: The consistent increase in equity suggests that the company is largely self-funding its growth through retained earnings, which is a hallmark of financial resilience. * Market Relevance: Operating in the cybersecurity sector, SektorCERT benefits from a continuously growing and critical market, which inherently contributes to its long-term resilience. While a full assessment would ideally include cash flow statements and debt levels, the available data points to a financially sound and resilient company.
Key strengths: Consistent Revenue Growth, Healthy Profitability, Solid Equity Base, Self-Funding Capacity, Market Relevance
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.