Thomasberg Management Consulting ApS
Denmark · owned by Thomasberg ApS (Denmark) · thomasberg.com · 11 vendors
Specialist in business and IT development for private and public companies. The company provides services including security and maturity analyses, strategies and implementation plans, solution design and implementation of business applications and platforms, and development of management practices, organization, competencies and processes.
Resilience scores
- Digital Sovereignty: 18
- Digital Resilience: 5
- Financial Resilience: 8.5
Technology vendors
- Google LLC — Technology — United States
- LeanIX — Technology — Germany
- Usercentrics GmbH — Technology — Germany
- and 8 more
Services catalogue
2 services in catalogue across 1 category; runs on 11 sub-vendors.
- Operations and Maintenance Adviser Framework
- Strategic and technical advice
Insights
Last updated 2026-09-13 · revision 14
11 direct vendors, 180 subvendors
Direct vendors by controlling owner country (sample)
- United States: 9
- Germany: 2
Subvendors by controlling owner country (sample)
- Ireland: 2
- United States: 127
- France: 2
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
The company shows high-medium migration readiness, benefiting from its small, agile size (7 employees) and strong financial growth which ensures funding for necessary transitions. The absence of a heavy legacy 'Internal Tech Stack' and the consumption of 36 external services suggests a cloud-native or SaaS-heavy operating model, which is significantly easier to migrate than monolithic on-premise architectures. However, readiness is constrained by strict regulatory requirements; as a Danish firm handling data for major clients (Vestas, Arla), GDPR compliance is 'High' risk and strictly limits data residency to the EU/EEA or adequate jurisdictions. Additionally, the reliance on US-based services (noted in Vendor HQ Countries) may require careful assessment of data transfer mechanisms (SCCs) during any infrastructure migration. The lack of specific vendor names (despite 36 services listed) creates a 'hidden lock-in' risk, as contract complexity cannot be fully assessed.
Compliance
3 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
GDPR applies to all EU-based companies processing personal data. As a Danish management consulting firm, Thomasberg processes employee data, client data, and potentially sensitive business information.
GDPR applies to all EU-based companies processing personal data. As a Danish management consulting firm, Thomasberg processes employee data, client data, and potentially sensitive business information. Non-compliance can result in fines up to 4% of annual turnover or €20M. Given their client base includes large corporations (Vestas, Arla, TV2), data protection is critical for maintaining trust and avoiding regulatory penalties.
SOC 2 (source) — Assessment Required
SOC2 is relevant for service providers handling client data. As a consulting firm working with large corporations and potentially handling sensitive business information, SOC2 compliance could be required by clients.
SOC2 is relevant for service providers handling client data. As a consulting firm working with large corporations and potentially handling sensitive business information, SOC2 compliance could be required by clients. Risk is medium as it's not legally mandated but may be contractually required for client relationships.
ISO 27001 (source) — Assessment Required
ISO 27001 is not legally mandated but is increasingly expected by enterprise clients for consulting firms handling sensitive information. Given their client base includes major corporations, certification could be a competitive requirement.
ISO 27001 is not legally mandated but is increasingly expected by enterprise clients for consulting firms handling sensitive information. Given their client base includes major corporations, certification could be a competitive requirement. Risk is medium as lack of certification could impact client acquisition but won't result in regulatory penalties.
Financials
Three-year financials
- 2025: gross profit DKK 2.21M, equity DKK 927K
- 2024: gross profit DKK 1.95M, equity DKK 1.04M
Financial Resilience Score: 8.5/10
Thomasberg Management Consulting ApS exhibits outstanding financial health, characterized by exceptional profitability and efficient operations. The company maintained a strong EBIT margin of approximately 59% in 2022, indicating significant pricing power and effective cost management. This profitability has translated into consistent growth, with EBIT more than doubling over a two-year period. The company's capital structure is remarkably robust, featuring a solvency ratio of 84.2% in 2022. This high level of equity relative to total assets demonstrates a very low reliance on external debt and a substantial buffer to absorb economic shocks. Growth is primarily funded through retained earnings, showcasing strong internal cash generation and a sustainable, organic expansion strategy. Despite its strengths, the firm is subject to risks typical of small, specialized advisory firms. These include potential sensitivity to macroeconomic cycles affecting M&A activity and a high dependency on key personnel. However, the overall financial trajectory remains very strong with improving solvency and profitability metrics.
Key strengths: Exceptional EBIT Margin (59% in 2022), High Solvency Ratio (84.2%), Strong Cash Flow from Retained Earnings, Consistent Organic Growth
Risk factors: Small firm size and specialization, Key personnel risk, Macroeconomic sensitivity (M&A and Corporate Finance cycles)
Workforce by country
- Denmark: 7
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.