Holm Security
Holm Security is a Swedish cybersecurity vendor that sells a unified Next-Gen Vulnerability Management Platform combining attack surface management with vulnerability scanning across IT, OT, cloud, web, API, and human assets, primarily serving European enterprises, mid-market firms, and municipalities seeking NIS2 and regulatory compliance.
- Company typePrivate
- Founded2015
- HeadquartersBromma, Sweden
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Holm Security does
Holm Security is a privately held Swedish cybersecurity company founded in 2015 and headquartered in Bromma, that sells a unified Next-Gen Vulnerability Management Platform combining Exposure Management, Vulnerability Management, Attack Surface Management (ASM), and External Attack Surface Management (EASM) under a single risk model. The platform is delivered as a set of integrated modules — System & Network Security, Web Application Security (DAST/SCA), Cloud Security (CSPM for AWS, Azure, GCP, Oracle, Microsoft 365), API Security, Phishing Simulation & Awareness Training, Active Directory Security (187 checks mapped to MITRE ATT&CK), OT Security (75+ SCADA vendors, 1,600+ vulnerability tests, industrial protocol awareness), and PCI ASV Scanning — covering more than 200,000 vulnerabilities across IT, OT, IoT, cloud, web, API, and human attack surfaces.
The platform uses an agentless architecture for cloud and external scanning, with native integrations to SIEM, CMDB, ticketing, patch management, and CI/CD systems. An AI-driven 24/7 Security Research team enriches vulnerability data beyond standard CVSS scoring to support prioritization and ransomware-related threat detection. Holm Security serves enterprises, mid-market firms, and municipalities across 15+ verticals (energy, healthcare, financial services, manufacturing, transportation, water supply, digital infrastructure, government, municipalities, retail, real estate, food, and education), with a particular emphasis on European organizations seeking compliance with NIS2, DORA, GDPR, ISO 27001, PCI DSS, CRA, CMMC, and NIST 800-171.
Holm Security monetizes through asset-based annual subscriptions — per active IP for system/network, per web application, per cloud resource, per unique API, per user for phishing training — with professional services for certification and success programs layered on top. The company goes to market via a direct enterprise field sales motion, an inside sales team handling demos and free trials, and a three-tier channel program (MSSP, reseller, distributor) with localized websites across Sweden, Norway, Denmark, Finland, Netherlands, Belgium, Germany, Poland, the UK, and Malaysia. The company has raised approximately $16.7M cumulatively across rounds from 2015 through 2022, with Subvenio Invest leading the most recent disclosed round in November 2022.
Holm Security firmographics
Firmographics- Name
- Holm Security
- Legal name
- Holm Security
- Website
- https://holmsecurity.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Holm Security is a Swedish cybersecurity vendor that sells a unified Next-Gen Vulnerability Management Platform combining attack surface management with vulnerability scanning across IT, OT, cloud, web, API, and human assets, primarily serving European enterprises, mid-market firms, and municipalities seeking NIS2 and regulatory compliance.
- Ownership category
- akta.pro rank
Holm Security industry classification
Industry- Product category
- Vulnerability Management Software
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Vulnerability Assessment & Scanning (HDADAHAA)
- akta.pro secondary industries
- Vulnerability Intelligence & Exploit Prediction (HDADAHAI), OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN), Vulnerability Management & Penetration Testing Services (BPAEADAD)
Keywords
Where Holm Security is headquartered
LocationHeadquarters
- HQ city
- Bromma
- HQ country
- Sweden
- HQ region
- Europe
Markets served
Holm Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Product Licensing - Asset-Based Subscription: Each product is licensed based on the number of assessed technical or human assets. System & Network Security licensed per active IPs (systems and computers in TCP/IP network). Web Application Security licensed per unique web application. Cloud Security licensed per cloud resource. API Security licensed per unique API application. Phishing Simulation licensed per user (email address). All features included with each product purchase.
- Professional Services: Certification Programs - training provided in Training Center for vulnerability management certification. Success Programs - continuous support and guidance from vulnerability management experts.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | System & Network Security - Licensed per active IP addresses (systems/computers in TCP/IP network) |
| Subscription | Annual | Web Application Security - Licensed per unique web application or URL |
| Subscription | Annual | Cloud Security - Licensed per cloud resource assessed |
| Subscription | Annual | API Security - Licensed per unique API application |
| Subscription | Annual | Phishing Simulation & Awareness Training - Licensed per user/email address |
Go-to-market motion2 records
Distribution channels6 records
Marketing channels7 records
Holm Security product offering
Product offeringCore offering
Holm Security provides a unified Next-Gen Vulnerability Management Platform (VMP) that combines Attack Surface Management (ASM/EASM) and vulnerability management in a single risk model. The platform identifies over 200,000 vulnerabilities across systems, networks, OT, IoT, cloud platforms, web applications, APIs, and human assets, with AI-driven threat intelligence, compliance support for NIS2/DORA/GDPR/ISO 27001/PCI DSS, and add-on modules including phishing simulation, Active Directory security, and OT-specific scanning.
Product overview
Holm Security offers a unified Next-Gen Vulnerability Management Platform (VMP) that combines exposure management and vulnerability management in a single risk model. The platform is organized around core platform capabilities (Exposure Management, Vulnerability Management, ASM, EASM) with integrated product modules including System & Network Security, Web Application Security, Cloud Security (CSPM), API Security, and Phishing Simulation & Awareness Training. Additional features include Active Directory Security, OT Security, and PCI ASV Scanning. All products are fully integrated within the platform to streamline workflows.
Differentiator
Problem solved
Functional benefit
Products and services
- Exposure Management Unified platform capability providing comprehensive insight into organizational cyber exposure through a single risk model, combining attack surface management with vulnerability management. Targets enterprise security and IT teams.
- Vulnerability Management Next-Gen Vulnerability Management Platform (VMP) that identifies vulnerabilities across the entire attack surface using a systematic, risk-based, and proactive approach. Targets enterprise, mid-market, and municipal security teams.
- Attack Surface Management (ASM) Automated discovery and continuous monitoring of assets to identify new assets, asset changes, blank spots, and shadow IT across the entire attack surface. Targets enterprise security teams.
- External Attack Surface Management (EASM) Automated discovery and monitoring of internet-facing and web-facing assets to minimize cyber risk exposure from external threats. Targets enterprise security teams.
- System & Network Security Identifies over 200,000 vulnerabilities across business-critical systems/servers, computers, network devices, OT, IoT, Kubernetes, Active Directory, cloud platforms, and office equipment. Licensed per active IP. Targets enterprise IT and security teams.
- Web Application Security Advanced scanning of modern web applications using Dynamic Application Security Testing (DAST) and Software Composition Analysis (SCA) to identify vulnerabilities including OWASP Top 10. Licensed per unique web application. Targets enterprise developers and security teams.
- Cloud Security (CSPM) Multi-cloud Cloud Security Posture Management (CSPM) supporting Azure, AWS, Google Cloud, Oracle Cloud, and Microsoft 365, identifying vulnerabilities and misconfigurations in cloud-native platforms. Licensed per cloud resource. Targets enterprise cloud and security teams.
- API Security Assessment of REST, GraphQL, and SOAP APIs for hundreds of vulnerabilities including OWASP API Top 10 to ensure robust security and protect critical data. Licensed per unique API application. Targets enterprise API and application security teams.
- Phishing Simulation & Awareness Training Phishing simulation with tailored awareness training programs and knowledge verification quizzes to build organizational resilience against email-based attacks and ransomware. Licensed per user/email address. Targets enterprise security awareness programs.
- Certification Programs Training provided in the Holm Security Training Center for vulnerability management certification. Targets enterprise and partner security practitioners.
- Success Programs Continuous support and guidance from Holm Security vulnerability management experts to drive successful platform outcomes. Targets enterprise and mid-market customers.
Quantifiable outcome
- Identifies over 200,000 vulnerabilities across attack surface
- +5 more outcomes
Companies that use Holm Security
Customer profileNamed customers12 records
Segments12 records
Ideal customer profiles3 records
Holm Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability2 records
Feature8 records
Holm Security partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- AkaticoreHolm Security provides ASV scanning through its partner Akati, which is a certified Approved Scanning Vendor for PCI DSS compliance scanning. Holm Security will become a certified ASV vendor in Q3 2026.
Scale indicators12 records
Recent moves6 records
Expansion highlights6 records
Holm Security competitors and assessment
Company assessmentDirect peers
- Tenable: Tenable is the market-leading vulnerability management vendor (Nessus, Tenable One), offering VM, ASM, and exposure management. Holm Security explicitly lists Tenable as a competitor, and both target enterprise security teams with continuous vulnerability assessment and unified risk views.
- Qualys: Qualys provides a cloud-based VM platform (Qualys VMDR) covering assets, vulnerabilities, and threat prioritization, with strong compliance reporting. Holm Security explicitly lists Qualys as a direct competitor in VM and web/cloud scanning for the same enterprise buyer.
- Rapid7: Rapid7 InsightVM offers vulnerability management with analytics, integrated threat intelligence, and cloud/containers coverage. Holm Security explicitly lists Rapid7 as a competitor targeting similar mid-market and enterprise security operations teams.
- Skybox Security: Skybox Security provides vulnerability management, attack surface visibility, and network modeling for large enterprises. Comparable as a peer in the exposure/vulnerability management category with emphasis on risk prioritization across hybrid environments.
Broad incumbents
- Microsoft Defender Vulnerability Management: Microsoft bundles vulnerability management into Defender for Endpoint and the broader Defender suite. Holm Security explicitly lists Microsoft as a competitor; Microsoft advantages are deep M365/Azure integration and aggressive bundling rather than VM specialization.
- CrowdStrike Falcon Spotlight: CrowdStrike offers Falcon Spotlight as part of its Falcon platform, integrating vulnerability assessment with EDR/next-gen AV. Comparable as a broad incumbent delivering VM as part of a wider endpoint/cloud security portfolio.
Emerging players
- Nozomi Networks: Nozomi Networks specializes in OT/IoT cybersecurity with deep industrial protocol coverage and asset visibility. Comparable as an emerging/OT-specialist peer to Holm Security's OT security module in critical infrastructure markets.
- Claroty: Claroty focuses on cyber-physical systems security for industrial, healthcare, and commercial environments. Comparable as an OT/ICS security peer whose vulnerability and asset discovery capabilities overlap with Holm Security's OT module.
Regional players
- Outpost24: Outpost24 is a European-based vulnerability management and threat intelligence vendor with EASM, VM, and pen testing. Highly comparable to Holm Security in geographic focus (Nordics/Europe), product scope, and target buyer profile.
Others
- Tenable.sc / Nessus (legacy note): Already represented via Tenable; listed to note overlap with pure on-prem Nessus scanner deployments that compete head-to-head with Holm Security's System & Network Security module.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Holm Security social profiles
Digital presenceHolm Security compliance and trust
Trust signalCompliance6 records
Holm Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Holm Security leadership team
Management profileNumber of profiles
Profiles5 records
Holm Security funding detail
Funding detailFunding overview
Funding rounds7 records
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Holm Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Holm Security
What does Holm Security do?
Holm Security provides a unified Next-Gen Vulnerability Management Platform (VMP) that combines Attack Surface Management (ASM/EASM) and vulnerability management in a single risk model. The platform identifies over 200,000 vulnerabilities across systems, networks, OT, IoT, cloud platforms, web applications, APIs, and human assets, with AI-driven threat intelligence, compliance support for NIS2/DORA/GDPR/ISO 27001/PCI DSS, and add-on modules including phishing simulation, Active Directory security, and OT-specific scanning.
Is Holm Security a public or private company?
Holm Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Holm Security founded?
Holm Security was founded in 2015. It employs 51 to 100 people.
Where is Holm Security based?
Holm Security is headquartered in Bromma, Sweden, in the Europe region.
How does Holm Security make money?
Two revenue lines are on record. Product Licensing - Asset-Based Subscription is the primary driver. The others are professional Services.
Who are Holm Security's main competitors?
Direct peers on record are Tenable, Qualys, Rapid7 and Skybox Security. Broad incumbents are Microsoft Defender Vulnerability Management and CrowdStrike Falcon Spotlight. Emerging players are Nozomi Networks and Claroty. Outpost24 is listed as a regional player. Tenable.sc / Nessus (legacy note) is listed as an others.
Does Holm Security have an API?
Yes. Holm Security provides a platform API that enables custom integrations tailored to specific organizational needs. The API supports creating custom integrations for SIEM, CMDB, patch management, ticketing systems, and CI/CD workflows.
What industry is Holm Security in?
Holm Security's product category is Vulnerability Management Software. Its primary akta.pro industry code is HDADAHAA, Vulnerability Assessment & Scanning, with a secondary code of HDADAHAI, Vulnerability Intelligence & Exploit Prediction. Its NAICS code is 5415 and its SIC code is 7370.