Truesec

Sweden · owned by IK Partners (United Kingdom) · www.truesec.com · 15 vendors

Truesec is a global cybersecurity company with a clear purpose: To create safety and sustainability in a digital world by preventing and minimizing cybercrime.

Resilience scores

Disruption prediction

Truesec has an estimated 17% probability of disruption in the next 6 months.

8 of Truesec's 15 vendors monitored for disruptions.

Technology vendors

Insights

Last updated 2026-07-23 · revision 9

15 direct vendors, 200 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Truesec exhibits high migration readiness, primarily driven by its modern and cloud-centric technology stack. Their extensive use of Microsoft Azure and Microsoft 365 indicates significant existing cloud adoption, which streamlines further cloud migrations. The internal tech stack includes a diverse array of best-of-breed security solutions (e.g., CrowdStrike, Vectra AI, SailPoint, Darktrace), suggesting a modular architecture that can facilitate component-wise migration. Their strong financial growth and stability, as indicated by 'Gasell' awards, provide the necessary resources to fund complex migration initiatives. Furthermore, Truesec's robust GDPR compliance framework, including safeguards for international data transfers, is a critical enabler for data migration within the EU/EEA, ensuring legal and privacy requirements are met. However, certain factors present challenges that prevent a perfect score. The 'Assessment Required' status for NIS2 and SOC2 compliance means that these regulatory requirements would need to be thoroughly addressed and integrated into any migration strategy to avoid potential disruptions or penalties. While the tech stack is diverse, the deep integration with the Microsoft ecosystem (Azure, M365, Sentinel) could lead to some vendor lock-in, potentially complicating migration to alternative cloud providers or platforms. Data residency requirements under GDPR, while well-managed, necessitate meticulous planning for any data transfers outside the EU/EEA. The contradictory 'Vendor Relationships' data ('Total Vendors: 0' vs. 'Vendor Geographic Diversity: 6 unique countries') makes a precise assessment of vendor lock-in risk challenging, but the diverse tech stack implies a manageable level of vendor dependency.

Compliance

8 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

Truesec provides cloud-delivered managed security services (MDR, SOC-as-a-service, managed identity security, managed threat exposure) to enterprise and public sector customers across multiple countries. SOC 2 is a widely expected assurance standard for technology service providers handling customer data in cloud environments. The risk is Medium because: (1) Enterprise and public sector customers increasingly require SOC 2 Type II reports as part of vendor due diligence; (2) Truesec's MDR platform processes sensitive security telemetry and potentially personal data from customer environments; (3) Absence of a SOC 2 report could be a competitive disadvantage and a procurement barrier, particularly for US-linked customers or multinational enterprises; (4) However, Truesec's ISO 27001 certification partially addresses the same control objectives and may substitute for SOC 2 in EU customer contexts.

Evidence: https://www.truesec.com/management-system-iso-certified, https://www.truesec.com/service/managed-detection-and-response

NIS2 (source) — Assessment Required

NIS2 (EU Directive 2022/2555, transposed into Swedish law as the Cybersäkerhetslagen) is highly likely to apply to Truesec on multiple grounds. First, Truesec qualifies as a 'Managed Security Service Provider' (MSSP) — a category explicitly listed under NIS2 Annex I as an Essential Entity under 'ICT service management (B2B)'. Second, Truesec operates critical digital infrastructure services (24/7 SOC, MDR, incident response) for essential and important entities across the Nordics, including energy companies (Vattenfall), financial institutions (Swedbank), and public sector bodies. Third, with 400+ employees and operations across five EU countries, Truesec clearly exceeds the medium enterprise threshold (50+ employees / €10M+ turnover). Non-compliance risk is High because: (a) NIS2 imposes significant obligations (incident reporting within 24/72 hours, supply chain security, board-level accountability, mandatory security measures); (b) penalties can reach €10M or 2% of global annual turnover for essential entities; (c) Swedish NIS2 transposition (Cybersäkerhetslagen) entered into force in January 2025 with active enforcement by NCSC Sweden (CERT-SE/MSB); (d) as a cybersecurity company serving critical infrastructure, Truesec is a high-profile target for regulatory scrutiny.

Evidence: https://www.truesec.com/who-we-are, https://www.truesec.com/management-system-iso-certified, https://www.truesec.com/service/strategic-advisory, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

Swedish Personal Data Act — Compliant

Sweden's data protection supervisory authority is IMY (Integritetsskyddsmyndigheten), which enforces GDPR in Sweden. Truesec's published privacy notice explicitly references the right to lodge complaints with supervisory authorities and links to the EDPB members list. The company has a dedicated privacy contact and demonstrates active GDPR compliance management. Risk is Low because Truesec has documented compliance measures and no public enforcement actions by IMY against Truesec have been identified.

Evidence: https://www.truesec.com/privacy-and-terms, https://www.imy.se/en/

Financials

Three-year financials

Financial Resilience Score: 7/10

Truesec demonstrates strong qualitative financial resilience despite the lack of publicly verified figures in this report. The company was awarded Gazelle Company status by Dagens Industri in 2025, which requires doubling revenue over four fiscal years, positive operating results each year, and organic growth. This external validation, combined with headcount doubling from ~200 employees in 2020 to 400+ in 2025/26, points to sustained profitable growth. Backing from FSN Capital (majority owner since 2021) provides financial firepower for M&A and scaling. Structural tailwinds support continued resilience: Nordic cybersecurity spending is growing double-digit annually, driven by NIS2, DORA, and rising ransomware. Truesec's recurring-revenue mix (MDR, Managed Threat Exposure, Managed Identity Security, IR Retainers) provides visibility, while a blue-chip customer base (Vattenfall, Swedbank, Coop, Addtech, Bufab, Solar, plus public sector) limits concentration risk. ISO 9001/14001/27001 certifications and MSSP Alert Top 250 listing reinforce reputational moat. Risks constraining a higher score include talent-cost inflation in scarce cybersecurity labor markets, project revenue lumpiness from event-driven Incident Response fees, geographic concentration in Sweden, integration risk from serial acquisitions, and PE ownership implying eventual exit pressure and potential debt on the balance sheet. Limited public disclosure also constrains external verification.

Key strengths: Gazelle Company status 2025 (doubled revenue over 4 years, positive operating result each year), FSN Capital majority ownership since 2021 providing M&A firepower, Recurring-revenue mix from MDR and managed services, Blue-chip customer base including Vattenfall, Swedbank, Coop, Structural double-digit growth in Nordic cybersecurity spending (NIS2, DORA), ISO 9001/14001/27001 certifications and MSSP Alert Top 250 listing, Headcount doubled from ~200 (2020) to 400+ (2025/26)

Risk factors: Talent-cost inflation in scarce cybersecurity labor market, Project revenue lumpiness from event-driven Incident Response, Geographic concentration heavily in Sweden, Integration risk from serial acquisitions (Cygate parts, Subset), PE ownership implies exit pressure and potential leverage, Limited public disclosure as a private company

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report