Tine Tuxen
Denmark · owned by Tinetuxen Holding ApS (Denmark) · tinetuxen.dk · 7 vendors
Tine Tuxen is a Danish independent IT security consultancy operated by Tine Tuxen, based in Holte, Denmark. The firm offers risk-based information security consulting services, including risk assessments, compliance guidance, and security strategy development for organisations. It takes a pragmatic, business-oriented approach to help clients meet regulatory requirements and improve their overall IT security posture.
Resilience scores
- Digital Sovereignty: 14
- Digital Resilience: 3
- Financial Resilience: 5
Disruption prediction
Tine Tuxen has an estimated 17% probability of disruption in the next 6 months.
1 of Tine Tuxen's 7 vendors monitored for disruptions.
Technology vendors
- Elegant Themes — Technology — United States
- LiteSpeed Technologies, Inc. — Technology — United States
- Mandrill (an Intuit company) — United States
- and 4 more
Insights
Last updated 2026-09-13 · revision 15
7 direct vendors, 45 subvendors
Direct vendors by controlling owner country (sample)
- United States: 5
- Cyprus: 1
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- Sweden: 1
- Norway: 1
- France: 1
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Tine Tuxen demonstrates medium migration readiness, characterized by a mix of challenges and opportunities. The primary challenge stems from the internal tech stack, which is based on WordPress. This is a monolithic content management system, not a cloud-native, containerized, or microservices-based architecture, implying that a migration to modern cloud infrastructure would likely require significant re-platforming or re-development efforts. Financial stability, with 'revenue: null' for 2022 and a sole employee, suggests limited financial resources to fund a complex migration project. The regulatory environment, particularly GDPR and the Danish Data Protection Act, along with potential client-specific data residency requirements (especially for public sector clients), adds complexity, necessitating careful planning for data location, transfer mechanisms, and compliance throughout any migration. However, several factors significantly enhance migration readiness. The company's small scale (sole consultant) means the volume of data and the complexity of internal systems are likely low, making the *scope* of a migration much simpler than for a larger enterprise. Crucially, the 'Total Vendors: 0' indicates no contractual vendor lock-in, which is a major advantage as it eliminates the need to untangle complex vendor agreements or incur exit fees. While there might be technical lock-in to the WordPress platform, the absence of contractual dependencies provides significant flexibility. Furthermore, the company's core business is cybersecurity and compliance, meaning Tine Tuxen possesses strong internal expertise in navigating regulatory requirements and implementing secure solutions, which is invaluable for planning and executing a compliant and secure migration.
Compliance
6 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
SOC 2 is a voluntary framework developed by the AICPA, primarily relevant for US-based cloud service providers and technology companies that store, process, or transmit customer data. TineTuxen ApS is a Danish consulting firm, not a cloud service provider. However, as a cybersecurity consultant, TineTuxen may access client systems and data during engagements, which could theoretically trigger client requests for SOC 2-equivalent assurance. In practice, SOC 2 is rarely required of individual consultants in the EU, where ISO 27001 is the dominant information security assurance framework. Risk is Low because: (1) TineTuxen is not a cloud/SaaS provider; (2) ISO 27001 is the EU-standard equivalent; (3) no client-facing SOC 2 requirement has been identified.
Evidence: https://tinetuxen.dk/ydelser/, https://tinetuxen.dk/cv/
ISO 27001 (source) — Assessment Required
ISO 27001 is highly relevant to TineTuxen ApS given that: (1) the company provides ISO 27001 audit and gap analysis services to clients; (2) the founder holds ISO 27001 Practitioner certification (2018); (3) the company's service portfolio explicitly includes ISO 27001 compliance assistance. However, no evidence was found that TineTuxen ApS itself holds a formal ISO 27001 certification for its own ISMS. This creates a credibility and reputational risk — a cybersecurity consultancy advising clients on ISO 27001 that is not itself certified may face client scrutiny. Risk is Medium because: (1) lack of own certification is a reputational and competitive risk in the cybersecurity consulting market; (2) clients may require their security consultants to demonstrate their own security posture; (3) the founder's certifications (CISSP, CISM, ISO 27001 Practitioner) partially mitigate this risk at the individual level.
Evidence: https://tinetuxen.dk/cv/, https://tinetuxen.dk/ydelser/, https://www.iso.org/standard/27001
Danish Data Protection Act — Partially Compliant
The Danish Data Protection Act supplements GDPR with national specifications and derogations. As a Danish entity, TineTuxen ApS must comply with both GDPR and the Danish DPA. The company's privacy policy references Datatilsynet as the supervisory authority, indicating awareness of Danish data protection law. Risk mirrors GDPR risk — Medium — due to the same gaps identified under GDPR (potential absence of RoPA, Article 28 DPAs with sub-consultants, and policy not updated since 2022).
Evidence: https://tinetuxen.dk/cookie-og-privatlivspolitik/, https://www.datatilsynet.dk/english, https://www.retsinformation.dk/eli/lta/2018/502
Financials
Three-year financials
- 2025: gross profit DKK 1.46M, EBIT DKK 589K, equity DKK 599K
- 2024: gross profit DKK 1.58M, EBIT DKK 723K, equity DKK 693K
- 2023: gross profit DKK 1.19M, EBIT DKK 257K, equity DKK 325K
Financial Resilience Score: 5/10
TineTuxen ApS is a micro-enterprise, single-consultant Danish cybersecurity advisory firm operating from Holte, Denmark. The company benefits from a very low fixed-cost base with no offices or staff to fund, meaning break-even revenue is low and the founder's senior specialization (20+ years at NNIT, PET, BRFkredit, NNE, Tryg) supports premium daily rates. Diversified income streams beyond core consulting—including teaching at Københavns Erhvervsakademi, external examiner roles for two censor corps, board membership at Dansk IT, and speaking engagements—help smooth cash flow. However, resilience is significantly constrained by absolute key-person risk: the company is effectively one person, and illness, burnout, or a career change would end revenue entirely. Growth is capped by the founder's billable hours with no operating leverage, customer concentration is likely high, and equity buffers are typically modest for a micro-ApS. Regulatory tailwinds from NIS2, DORA, and ISO 27001 demand support near-term outlook, and public-sector references (Hovedstadens Beredskab, Trafikstyrelsen) indicate a stable, credit-worthy customer base.
Key strengths: Very low fixed-cost base with no offices or staff, Senior specialization with elite certifications (CISSP, CISM, GCCC, ISO 27001, ISO 9001 Lead Auditor), Diversified income: consulting + teaching (KEA) + censor roles + board fees + speaking, Strong regulatory tailwinds (NIS2, DORA, ISO 27001), Danish public-sector client base (Hovedstadens Beredskab, Trafikstyrelsen), 20+ years of industry experience at NNIT, PET, BRFkredit, NNE, Tryg
Risk factors: Total key-person risk — company is effectively one person, No scale or operating leverage; growth capped by billable hours, Likely high customer concentration, Cyclicality of discretionary consulting budgets, Limited financial buffer typical for micro-ApS, ~100% geographic concentration in Denmark
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Information-security advisory / ISO 27001 implementation and audit: 40%
- Risk assessments and risk-management frameworks: 20%
- Compliance advisory (GDPR, NIS2): 15%
- Teaching at KEA: 10%
- Censor/examiner fees: 8%
- Board fees and speaking engagements: 7%
Workforce by country
- Denmark: 1
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.