TrueSec
Truesec is a Nordic-headquartered cybersecurity services firm with 350+ specialists across Sweden, Denmark, Finland, and Germany, delivering 24/7 managed detection and response, incident response, offensive security, and identity services from the largest SOC in the Nordics to roughly 250 enterprise and public-sector clients.
- Company typePrivate
- Founded2005
- HeadquartersRedmond, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What TrueSec does
Truesec is a Stockholm-headquartered cybersecurity services firm founded in 2005 by Marcus Murray, operating across Sweden, Denmark, Finland, and Germany with roughly 350 specialists. The company delivers 24/7 managed detection and response (MDR) from what it describes as the largest Security Operations Center in the Nordics, complemented by incident response retainers, digital forensics, offensive security, identity and access management, threat intelligence, OT security, cloud security, and strategic advisory services. Its customer base spans public sector (including Swedish municipalities), energy (Vattenfall), financial services (Swedbank), manufacturing (Addtech, Solar, Bufab), healthcare (Stockholms Sjukhem), defense (SRK), and space (Swedish Space Corporation), with approximately 250 organizations protected.
The core technology is the proprietary Truesec Cybersecurity Platform, which integrates custom detection rules built from frontline incident response experience with leading third-party security stacks including Microsoft Sentinel/Defender, CrowdStrike Falcon, Vectra, SailPoint, and Nozomi Networks. Truesec positions itself as human-led and AI-augmented, marketing agentic AI capabilities within its MDR service, and it publishes an annual 80-page Threat Intelligence Report as both a thought leadership and demand generation asset.
Revenue is generated through managed services contracts (MDR, managed identity, managed threat exposure), professional services and incident response retainers, and subscription-based identity governance services. All engagements are sold via direct enterprise sales with custom pricing; no self-serve or product-led growth motion exists. Recent strategic moves include the acquisitions of Danish offensive security firm Banshie (June 2025) and critical infrastructure secure systems specialist Subset (April 2026), a CEO transition to Karin Hagman (May 2025), the appointment of a new CFO and CRO in 2026, and the formalization of an OT security partnership with Nozomi Networks. Truesec is privately held, ISO 9001/14001/27001 certified, and a member of Trusted Introducer and FIRST.
TrueSec firmographics
Firmographics- Name
- TrueSec
- Legal name
- Truesec
- Website
- https://truesec.se
- Company type
- Private
- Founded year
- 2005
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Truesec is a Nordic-headquartered cybersecurity services firm with 350+ specialists across Sweden, Denmark, Finland, and Germany, delivering 24/7 managed detection and response, incident response, offensive security, and identity services from the largest SOC in the Nordics to roughly 250 enterprise and public-sector clients.
- Ownership category
- akta.pro rank
TrueSec industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (54151), Security Systems Services (56162)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Communications Services, Nec (4899)
- akta.pro primary industry
- Security Incident Response (IR) & Digital Forensics Services (BPAEADAI)
- akta.pro secondary industries
- Network Security Services (Firewall/VPN/ZTNA/SASE Integration) (BPAEAEAG), Secure Communications & Encryption for Utility Networks (VPN, PKI, Key Management) (EUADANAG), Secrets Management (Passwords, API Keys, Tokens) (HDADAFAD)
Keywords
Where TrueSec is headquartered
LocationHeadquarters
- HQ city
- Redmond
- HQ country
- United States
- HQ region
- North America
Offices6 records
Markets served
TrueSec business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Managed Detection and Response (MDR): 24/7 managed security monitoring service delivered through Truesec's Security Operations Center (SOC). The largest SOC in the Nordics monitors networks, endpoints, logs and cloud environments. Service is delivered as a managed service contract, typically multi-year engagements with enterprise clients. Provides continuous protection with agentic AI and human expertise.
- Incident Response and Digital Forensics: Emergency incident response services available 24/7 across Sweden, Denmark, Finland, Germany and internationally. Includes incident management, digital forensics, infrastructure recovery, and ransomware handling. Can be contracted as retainer or ad-hoc engagements.
- Consulting Services: Advisory and consulting services spanning offensive security, application security, strategic consulting, cloud security, AI & data security, infrastructure & network security, identity and access management (IAM), and threat intelligence. Sold as project-based or retainer engagements.
- Managed Identity Security: IAM-as-a-managed-service offering based on SailPoint platform. Provides identity governance, automated lifecycle management, and access reviews as a monthly subscription service.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Annual | Custom enterprise pricing — no public tiers disclosed |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
TrueSec product offering
Product offeringCore offering
Truesec delivers 24/7 human-led, AI-augmented cybersecurity services including Managed Detection and Response (MDR), Managed Threat Exposure (MTE), Incident Response and Digital Forensics, Offensive Security, Identity and Access Management (IAM), Threat Intelligence, OT Security, Cloud Security, and strategic advisory. These services are powered by the proprietary Truesec Cybersecurity Platform and delivered from the largest Security Operations Center in the Nordics, targeting enterprise and public sector organizations across Northern Europe.
Product overview
Truesec offers a comprehensive cybersecurity portfolio combining managed services, professional consulting, and a proprietary technology platform. The core offering centers on Managed Detection and Response (MDR) powered by the Truesec Cybersecurity Platform, supplemented by 24/7 SOC monitoring and Managed Threat Exposure (MTE). The consulting arm covers offensive security, IAM, threat intelligence, cloud security, OT security, and infrastructure hardening. All capabilities are delivered by over 350 specialists across Sweden, Denmark, Finland, and Germany, supported by technology partnerships with Microsoft, SailPoint, and Nozomi Networks.
Differentiator
Problem solved
Functional benefit
Products and services
- Managed Detection and Response (MDR) 24/7 human-led, AI-driven security monitoring covering networks, endpoints, logs, and cloud environments, powered by the Truesec Cybersecurity Platform and integrating Microsoft, CrowdStrike, and other leading security technologies. Targeted at enterprise and public sector organizations requiring continuous cybersecurity protection.
- Managed Threat Exposure (MTE) Proactive defense service identifying and reducing attack surface across external-facing assets, credentials, and vulnerabilities. For organizations needing continuous exposure management.
- Incident Response Retainer Pre-negotiated, on-demand access to Truesec's CSIRT team for rapid incident response during cyber emergencies. Available across Sweden, Denmark, Finland, Germany, and internationally.
- Digital Forensics and Incident Response (DFIR) Evidence preservation, root cause analysis, and forensic investigation services with reporting to management, insurers, and authorities. For organizations that have experienced a cyber incident and need forensic support.
- Incident Management Preparation Planning and readiness services including incident response plan development, tabletop exercises, and training for organizational crisis response. For organizations seeking to improve their incident readiness.
- Offensive Security Penetration testing, red team exercises, and vulnerability assessments simulating real-world attacks to identify security weaknesses. For organizations seeking to validate their security posture.
- Identity and Access Management (IAM) Full lifecycle identity security including advisory, implementation, and managed services for identity governance built on SailPoint and Privileged Access Management using Segura. For organizations seeking to secure and automate identity lifecycles.
- Managed Identity Security IAM-as-a-managed-service based on the SailPoint platform providing identity governance, automated lifecycle management, and access reviews with predictable monthly cost. For organizations wanting identity management delivered as a managed subscription.
- Threat Intelligence Services Intelligence-driven services including Intelligence as a Service, Executive Services for key personnel protection, and Intelligence Advisory for building internal intelligence capabilities. For organizations needing actionable threat intelligence.
- OT Security (Operational Technology Security) Cybersecurity solutions for operational technology environments covering manufacturing, energy, food, mining, and transport sectors with 24/7 monitoring and NIS2/IEC 62443 compliance. For critical infrastructure operators.
- Cloud Security Security services for cloud and on-premises environments protecting data, applications, and infrastructure against unauthorized access. For organizations operating hybrid or cloud-native environments.
- AI & Data Security Services securing AI systems, data pipelines, and critical information assets against misuse, leakage, and attacks during AI implementation. For organizations deploying AI in production environments.
- Infrastructure & Network Security Services covering Active Directory tiering implementation, system hardening, and network segmentation to protect critical infrastructure. For organizations needing foundational infrastructure security improvements.
- Application Security
Quantifiable outcome
- 3x faster business recovery than industry average (incident response)
- +3 more outcomes
Companies that use TrueSec
Customer profileNamed customers10 records
Segments3 records
Ideal customer profiles3 records
TrueSec technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
Feature4 records
TrueSec partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered minor and core.
- SubsetminorTruesec Group acquired Subset to strengthen capabilities in developing secure systems for critical infrastructure. While this is an acquisition, Subset functions as a strategic capability addition to Truesec Group's offerings for critical infrastructure clients.
- VermiculusminorVermiculus partnered with Truesec to enhance its cybersecurity resilience. The collaboration aims to ensure Vermiculus' IT solutions meet international standards and provide enhanced security for their financial markets services. Vermiculus operates in the financial sector and requires high-security standards.
- Nozomi NetworkscoreThrough partnership with Nozomi Networks, Truesec strengthened its MDR services for OT (Operational Technology) environments. Nozomi's platform combines network and endpoint visibility, threat detection, and AI-driven analytics. The partnership enhances Truesec's ability to protect critical infrastructure against evolving cyber threats.
- MicrosoftcoreMicrosoft is a preferred technology partner for Truesec's cybersecurity platform and MDR services. Truesec leverages Microsoft security technologies (including Microsoft Sentinel, Defender, and Entra ID) as part of its integrated service delivery. The partnership is central to Truesec's managed services architecture.
- CrowdStrikecoreCrowdStrike is a preferred technology partner providing Falcon platform capabilities integrated into Truesec's MDR services. Partnership enables Truesec to deliver endpoint detection and response using CrowdStrike's EDR/XDR technology as a key component of its security platform.
- VectracoreVectra is a key technology partner providing AI-driven network detection and response capabilities. Truesec has a longstanding partnership with Vectra and was named Vectra's Growth Partner of the Year in both 2023 and 2024 in the Nordics.
- SailPointcoreTruesec's Managed Identity Security service is built on the SailPoint identity governance platform. SailPoint is the core technology platform for Truesec's IAM-as-a-managed-service offering, providing identity lifecycle management, access certifications, and governance automation.
- Trusted IntroducercoreTruesec's CSIRT team is a certified member of Trusted Introducer, a pan-European network of trusted CERTs and security teams. This certification provides formal recognition of Truesec's incident response capabilities and operational standards.
- No More RansomcoreTruesec CSIRT is a proud associate partner of No More Ransom, an initiative led by Europol and law enforcement agencies to help victims of ransomware recover their data without paying ransom. Demonstrates Truesec's commitment to combating cybercrime.
- FIRST (Forum of Incident Response and Security Teams)coreTruesec's CSIRT team is a certified member of FIRST, a global forum of incident response and security teams. Membership enables collaboration with global peers and access to best practices in incident response.
Scale indicators10 records
Recent moves7 records
Expansion highlights6 records
TrueSec competitors and assessment
Company assessmentDirect peers
- Expel: US-headquartered MDR and managed detection provider with strong cloud-native detection capabilities and a partner-friendly channel. Comparable on managed detection/response delivery model and customer-segment focus on mid-market and enterprise.
- Sentor: Swedish-headquartered cybersecurity services firm focused on managed detection and response, penetration testing, and security consulting. Direct Nordic competitor with similar customer base and enterprise sales motion.
- Nixu: Finnish cybersecurity services firm specializing in identity management, incident response, and OT/ICS security across the Nordics. Highly comparable on services mix (IAM, IR, OT) and on Nordic public-sector exposure; recently integrated with Accenture.
- WithSecure: Finnish-headquartered cybersecurity firm (formerly F-Secure's corporate business) offering MDR, incident response, and consulting across the Nordics and Europe. Direct competitor in the Nordic enterprise and public-sector MSSP market with similar service portfolio and customer segments.
- Orange Cyberdefense: European MSSP and division of Orange, providing managed detection and response, incident response, and threat intelligence across multiple European geographies. Directly comparable on the managed SOC, IR, and threat intelligence offerings.
- Arctic Wolf: Leading global MDR provider delivering 24/7 managed detection and response via a concierge security operations model. Closest direct competitor on the core MDR-as-a-service proposition and threat intelligence–driven SOC operations.
Broad incumbents
- Microsoft (Defender Experts / Security): Hyperscaler with Microsoft Sentinel, Defender, and Defender Experts for XDR managed services. Central technology partner to Truesec but also a structural competitor as enterprises adopt Defender Experts for XDR directly, potentially disintermediating regional MSSPs.
- CrowdStrike: Global cybersecurity incumbent and key Truesec technology partner offering the Falcon platform plus CrowdStrike Falcon Complete MDR. Comparable on endpoint/XDR/MDR capabilities and increasingly competes with Truesec's own MDR through direct managed services.
- Mandiant (Google Cloud): Global incident response and threat intelligence leader, now part of Google Cloud. Direct competitor on incident response retainers, DFIR, and threat intelligence advisory, particularly for enterprise and government clients in Europe.
Others
- Accenture Security: Global systems integrator and cybersecurity services arm of Accenture, which acquired Nixu. Comparable on enterprise security consulting and managed services, and is an indirect peer through the Nordic market overlap and ecosystem relationships.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
TrueSec social profiles
Digital presenceTrueSec compliance and trust
Trust signalCompliance6 records
TrueSec financial estimates
Financial estimateRevenue estimate
Valuation estimate
TrueSec leadership team
Management profileNumber of profiles
Profiles12 records
TrueSec subsidiaries and ownership
Company hierarchySubsidiaries2 records
TrueSec funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
TrueSec M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about TrueSec
What does TrueSec do?
Truesec delivers 24/7 human-led, AI-augmented cybersecurity services including Managed Detection and Response (MDR), Managed Threat Exposure (MTE), Incident Response and Digital Forensics, Offensive Security, Identity and Access Management (IAM), Threat Intelligence, OT Security, Cloud Security, and strategic advisory. These services are powered by the proprietary Truesec Cybersecurity Platform and delivered from the largest Security Operations Center in the Nordics, targeting enterprise and public sector organizations across Northern Europe.
Is TrueSec a public or private company?
TrueSec is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was TrueSec founded?
TrueSec was founded in 2005. It employs 11 to 50 people.
Where is TrueSec based?
TrueSec is headquartered in Redmond, United States, in the North America region.
How does TrueSec make money?
Four revenue lines are on record. Managed Detection and Response (MDR) is the primary driver. The others are incident Response and Digital Forensics, consulting Services and managed Identity Security.
Who are TrueSec's main competitors?
Direct peers on record are Expel, Sentor, Nixu, WithSecure, Orange Cyberdefense and Arctic Wolf. Broad incumbents are Microsoft (Defender Experts / Security), CrowdStrike and Mandiant (Google Cloud). Accenture Security is listed as an others.
Does TrueSec have an API?
No public API is recorded for TrueSec.
What industry is TrueSec in?
TrueSec's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEADAI, Security Incident Response (IR) & Digital Forensics Services, with a secondary code of BPAEAEAG, Network Security Services (Firewall/VPN/ZTNA/SASE Integration). Its NAICS code is 54151 and its SIC code is 7370.