CSIS Security Group
CSIS Security Group provides intelligence-driven 24/7 Managed Detection and Response, incident response, threat intelligence, and digital risk protection services to mid-market and enterprise organizations across Europe, operating from offices in Denmark, Sweden, the UK, and the Netherlands as part of the Allurity platform.
- Company typePrivate
- Founded2003
- HeadquartersCopenhagen, Denmark
- Headcount51–100
- GTM typeB2B
- OfferingServices
What CSIS Security Group does
CSIS Security Group A/S is a Denmark-headquartered cybersecurity services firm founded in 2003, operating across Copenhagen, Skanderborg, Stockholm, London, and Amsterdam. It delivers a portfolio built around three pillars: Managed Detection and Response (MDR) delivered in three subscription tiers (Base, Pro, Elite, the last including an Incident Response guarantee); Emergency Response Consulting and Retainers for breach and ransomware incidents; and Security Consulting (AD, Cloud, Compromise, Assume Breach, NIS2 assessments). Adjacent lines include Cyber Threat Intelligence (Cyber Defence Feed, Threat Insights, Threat Cloud), Digital Risk Protection anchored by the proprietary phishdb anti-phishing database, and Specialized Services for OT cybersecurity and NIS2.
The technology stack combines a 24/7 intelligence-driven SOC with proprietary tooling: Chronos and Cirk forensics platforms, the phishdb database, 150+ custom detection rules for Microsoft Sentinel, Machine Readable Intelligence feeds, and integrations with Microsoft Defender XDR, Darktrace, Nozomi Networks, and CrowdStrike. Detection content is authored by the in-house research and IR teams and refined against live incident data, which the company reports yields approximately 2.6 billion compromised credentials recovered and 4,500+ potential breaches mitigated per month.
The business model is predominantly subscription-recurring (MDR and Cyber Defence Feed contracts on annual billing cadence), supplemented by retainer-based Emergency Response, project-based Security Consulting, and revenue from the 13th-annual Cyberhagen conference and Threat Matrix reports. Customers span banking and financial services (NatWest), energy and utilities (Vestas, Hempel), manufacturing (Palsgaard, DLF Seeds), government (Norddjurs Municipality, KBH Mærke), healthcare (Amgros), transport and logistics (RDG, Danx), and technology (Fellowmind). CSIS is a wholly-owned subsidiary of Allurity AB, the Trill Impact-backed European cybersecurity platform comprising 11 companies across 18 countries, and acquired UK-based Security Alliance Limited (SecAlliance) in September 2024 to deepen its CTI and CBEST-eligible capability.
CSIS Security Group firmographics
Firmographics- Name
- CSIS Security Group
- Legal name
- CSIS Security Group A/S
- Website
- https://csis.com
- Company type
- Private
- Founded year
- 2003
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- CSIS Security Group provides intelligence-driven 24/7 Managed Detection and Response, incident response, threat intelligence, and digital risk protection services to mid-market and enterprise organizations across Europe, operating from offices in Denmark, Sweden, the UK, and the Netherlands as part of the Allurity platform.
- Ownership category
- akta.pro rank
CSIS Security Group industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Security Systems Services (except Locksmiths) (561621), Security Systems Services (56162), Investigation and Security Services (5616)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Managed Detection & Response (MDR) & SOC Services (HDADAGAG)
- akta.pro secondary industries
- Cybersecurity & Identity Consulting (BPAHAEAG), Cybersecurity Support Operations (SOC Triage, Incident Intake) (BPAAACAF), Executive/Board Security Advisory & Risk Briefings (BPAKADAK)
Keywords
Where CSIS Security Group is headquartered
LocationHeadquarters
- HQ city
- Copenhagen
- HQ country
- Denmark
- HQ region
- Europe
Offices5 records
Markets served
CSIS Security Group business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Managed Detection and Response (MDR): 24/7 continuous monitoring, detection, and response services delivered across three tiers: MDR Base (foundational), MDR Pro (advanced), and MDR Elite (comprehensive with IR guarantee). Revenue is recurring subscription-based, typically annual contracts with enterprise clients.
- Emergency Response Retainers: Guaranteed immediate and round-the-clock access to incident response capability. Retainer-based model ensuring rapid response when security incidents occur.
- Security Consulting: Professional services including AD Security Assessment, Compromise Assessment, Assume Breach exercises, Cloud Security Assessment, and NIS2 compliance services.
- Digital Risk Protection: Anti-phishing services and threat monitors protecting organizations from brand impersonation and digital fraud.
- Cyber Threat Intelligence: Threat intelligence products including Cyber Defence Feed, Threat Insights, and Threat Cloud. Delivered through SecAlliance acquisition.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | MDR Base: Continuous 24/7 protection with automated threat monitoring and remediation for low/medium alerts, expert intervention for high/critical threats. |
| Subscription | Annual | MDR Pro: Advanced proactive threat detection and response for mid-sized enterprises with dedicated security teams. |
| Subscription | Annual | MDR Elite: Comprehensive guaranteed protection with Incident Response guarantee and proactive assessments. |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels10 records
CSIS Security Group product offering
Product offeringCore offering
CSIS Security Group provides intelligence-driven cybersecurity services delivered through 24/7 Managed Detection and Response (MDR) across three tiers (Base, Pro, Elite), Emergency Response Consulting and guaranteed Retainers, Digital Risk Protection (Anti-Phishing via phishdb and Threat Monitors), Security Consulting (AD Security Assessment, Compromise Assessment, Assume Breach, Cloud Security Assessment, NIS2 compliance), and Cyber Threat Intelligence products (Cyber Defence Feed, Threat Insights, Threat Cloud) augmented by the SecAlliance acquisition. Services are sold primarily as annual subscriptions, retainer-based emergency response agreements, and project-based consulting engagements to mid-market and enterprise clients across Europe.
Product overview
CSIS Security Group offers a unified portfolio of cybersecurity services organized around three core pillars: Managed Detection and Response (MDR), Emergency Response, and Security Consulting. The MDR service is delivered through three tiers (Base, Pro, Elite) utilizing detection technologies including Microsoft Sentinel, Microsoft Defender XDR, and Darktrace. The company provides threat intelligence through its Cyber Defence Feed, Threat Insights, and Threat Cloud products, significantly enhanced by the 2024 acquisition of SecAlliance. Consulting services span AD Security Assessment, Compromise Assessment, Assume Breach, and Cloud Security Assessment. The Emergency Response capability includes both on-demand consulting and retainer-based guaranteed access. Specialized offerings include NIS2 compliance services, OT cybersecurity, Executive Crisis Readiness training, and proprietary forensics tools (Chronos, Cirk). The company also publishes bi-annual Threat Matrix Reports and hosts the Cyberhagen annual conference.
Differentiator
Problem solved
Functional benefit
Products and services
- Managed Detection and Response (MDR) Intelligence-driven 24/7 Managed Detection and Response service for networks, endpoints, and cloud environments. Delivered across three tiers (MDR Base, MDR Pro, MDR Elite) using detection technologies including Microsoft Sentinel, Microsoft Defender XDR, and Darktrace, with CSIS-developed custom detection rules and guaranteed incident response in the Elite tier.
- SOC Escalation SOC escalation service providing expert analyst intervention for high and critical threats beyond automated monitoring capabilities.
- SIEM Acceleration Service to accelerate SIEM implementation and optimization, including delivery and tuning of 150+ custom detection rules for Microsoft Sentinel guided by CSIS research and incident response teams.
- XDR Acceleration Extended Detection and Response acceleration services enhancing detection capabilities across multi-vendor XDR environments.
- Anti-Phishing (Digital Risk Protection) Anti-phishing service protecting organizations with significant online presence (banks, logistics, eCommerce, government) from phishing attacks, leveraging the proprietary phishdb database.
- Threat Monitors (Digital Risk Protection) Digital risk protection service providing continuous monitoring and actionable threat intelligence to leading companies worldwide.
- AD Security Assessment Active Directory security assessment identifying vulnerabilities and misconfigurations in enterprise AD environments.
- Compromise Assessment Comprehensive assessment to determine whether an organization has been compromised or is currently under attack.
- Assume Breach Security consulting service based on the 'assume breach' paradigm, testing organizational resilience against advanced threats.
- Cloud Security Assessment Assessment of cloud infrastructure security posture and configurations across multi-cloud environments.
- Emergency Response Consulting Expert incident response consulting with rapid engagement of world-class professionals to support business continuity restoration during security incidents.
- Emergency Response Retainers Retainer agreements providing guaranteed immediate and round-the-clock access to CSIS incident response capabilities, including the IR cost guarantee backing the MDR Elite tier.
- Cyber Defence Feed Proprietary threat intelligence feed that proactively blocks malicious indicators and integrates with firewalls, SIEMs, and security tools.
- Threat Insights Threat intelligence offering providing detailed insights into threat actors, their tactics, techniques, and procedures (TTPs), and emerging cyber risks.
- Threat Cloud Cloud-based threat intelligence platform aggregating and analyzing threat data from multiple sources.
- NIS2 Compliance Services Specialized services helping organizations comply with EU NIS2 Directive cybersecurity requirements.
- OT Cybersecurity Services Operational Technology cybersecurity services protecting industrial control systems and OT environments.
- Executive Crisis Readiness Executive training program developed in collaboration with Delta Crisis Management to prepare leadership teams for cyber crises through realistic scenario-based exercises and ransomware negotiation training.
Quantifiable outcome
- 2.6 billion compromised credentials recovered monthly
- +4 more outcomes
Companies that use CSIS Security Group
Customer profileNamed customers13 records
Segments7 records
Ideal customer profiles5 records
CSIS Security Group technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability6 records
Feature6 records
CSIS Security Group partnerships and signals
Strategic signalPartnerships
15 partnerships are on record, tiered core and minor.
- MicrosoftcoreMicrosoft Security Solutions Partner with Threat Detection Specialism. Deep integration with Microsoft Sentinel, Defender XDR, and Azure security stack. Provides enhanced security posture for customers using Microsoft technologies.
- DarktracecoreDarktrace Elite Partner and member of Darktrace Defenders Partner Program. Provides AI-driven cybersecurity solutions integration for network and OT security monitoring.
- Nozomi NetworkscoreTechnology partnership for OT (Operational Technology) cybersecurity services, providing industrial control system and IoT security monitoring capabilities.
- CrowdStrikecoreTechnology partnership for endpoint protection and threat intelligence integration with CrowdStrike Falcon platform.
- Delta Crisis ManagementcoreService partnership for Executive Crisis Readiness program. Collaboration to deliver cyber crisis management training and support to executive leadership teams. Partnership combines CSIS cybersecurity expertise with Delta's negotiation and crisis management capabilities.
- AspITminorTalent development partnership supporting individuals with autism spectrum disorder (ASD) access to the labor market in cybersecurity roles.
- Girls in ITminorNetwork for women studying or working in IT, supporting gender balance in cybersecurity through workshops and visibility initiatives.
- CyberskillsminorCybersecurity talent pipeline development through CTF events, training, and workshops targeting young people before career decisions.
- Women4Cyber DenmarkminorNon-profit foundation promoting women in cybersecurity. Partnership supports participation and visibility of women in the field.
- CISL (Cyber Information Security Leader)minorLeadership development program for security leaders. CSIS CEO contributes as guest speaker to develop strong security leadership in organizations.
- Shadowserver FoundationcoreAlliance Partnership for global threat intelligence sharing and collaborative effort to make the internet more secure by detecting and reporting malicious activity.
- APWG (Anti-Phishing Working Group)coreSponsor Member contributing research and data to unify global response to cybercrime through data exchange and research.
- Danish National Coordination Centre for Cybersecurity (NCC)coreProfessional network membership advancing national cybersecurity initiatives and fostering collaboration across sectors in Denmark and Europe.
- NCFTA (National Cyber Forensics Training Alliance)minorCollaboration with trusted alliance of business and law enforcement through data provision to disrupt cybercrime.
- Delta Crisis ManagementcoreJoint Executive Crisis Readiness program developed in collaboration with Delta Crisis Management. Combines CSIS cybersecurity expertise with Delta's negotiation expertise (including hostage negotiators) to prepare executive leadership for cyber crises.
Scale indicators10 records
Recent moves7 records
Expansion highlights6 records
CSIS Security Group competitors and assessment
Company assessmentDirect peers
- Trustwave: Global MDR, incident response, and threat intelligence provider serving mid-market and enterprise customers — operating in adjacent European and global markets to CSIS.
- ReliaQuest: MDR and security operations platform vendor competing for enterprise SOC modernization budgets — comparable in scope and customer profile to CSIS.
- NCC Group: UK-headquartered cybersecurity consulting and managed services firm with deep European regulatory credentials and IR capabilities — a close functional and geographic peer to CSIS.
- Withsecure: Helsinki-based pure-play cybersecurity services and managed detection & response provider, sharing CSIS's Nordic roots, European enterprise focus, and subscription MDR positioning.
- Arctic Wolf: Pure-play MDR provider with a 24/7 SOC and concierge delivery model; competes head-on with CSIS in mid-market and enterprise MDR across Europe and globally.
- eSentire: Pure-play MDR vendor delivering 24/7 threat detection, investigation, and response — a direct competitor to CSIS's core MDR Base/Pro/Elite offering.
- Expel: MDR-focused provider built on transparent, customer-facing SOC operations; overlaps with CSIS in serving mid-market to enterprise customers needing 24/7 coverage.
- Orange Cyberdefense: European cybersecurity services arm of Orange with global SOC, incident response, and threat intelligence — directly comparable European-headquartered MDR and CTI competitor.
- DNV Cyber (formerly Nixu): Acquired Nordic cybersecurity services firm serving regulated enterprises across Northern Europe — directly comparable to CSIS in geography, verticals, and service mix.
Broad incumbents
- Sophos (MDR / Sophos MDR): Broad endpoint and network security incumbent offering bundled MDR as part of its wider portfolio — competing with CSIS particularly where customers seek single-vendor consolidation.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks7 records
Key highlights7 records
Customer concentration
CSIS Security Group social profiles
Digital presenceCSIS Security Group compliance and trust
Trust signalCompliance10 records
CSIS Security Group financial estimates
Financial estimateRevenue estimate
Valuation estimate
CSIS Security Group leadership team
Management profileNumber of profiles
Profiles10 records
CSIS Security Group subsidiaries and ownership
Company hierarchySubsidiaries1 record
CSIS Security Group funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CSIS Security Group M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CSIS Security Group
What does CSIS Security Group do?
CSIS Security Group provides intelligence-driven cybersecurity services delivered through 24/7 Managed Detection and Response (MDR) across three tiers (Base, Pro, Elite), Emergency Response Consulting and guaranteed Retainers, Digital Risk Protection (Anti-Phishing via phishdb and Threat Monitors), Security Consulting (AD Security Assessment, Compromise Assessment, Assume Breach, Cloud Security Assessment, NIS2 compliance), and Cyber Threat Intelligence products (Cyber Defence Feed, Threat Insights, Threat Cloud) augmented by the SecAlliance acquisition. Services are sold primarily as annual subscriptions, retainer-based emergency response agreements, and project-based consulting engagements to mid-market and enterprise clients across Europe.
Is CSIS Security Group a public or private company?
CSIS Security Group is a private company. It is classified as private equity controlled and is currently operating.
When was CSIS Security Group founded?
CSIS Security Group was founded in 2003. It employs 51 to 100 people.
Where is CSIS Security Group based?
CSIS Security Group is headquartered in Copenhagen, Denmark, in the Europe region.
How does CSIS Security Group make money?
Five revenue lines are on record. Managed Detection and Response (MDR) is the primary driver. The others are emergency Response Retainers, security Consulting, digital Risk Protection and cyber Threat Intelligence.
Who are CSIS Security Group's main competitors?
Direct peers on record are Trustwave, ReliaQuest, NCC Group, Withsecure, Arctic Wolf, eSentire, Expel, Orange Cyberdefense and DNV Cyber (formerly Nixu). Sophos (MDR / Sophos MDR) is listed as a broad incumbent.
Does CSIS Security Group have an API?
No public API is recorded for CSIS Security Group.
What industry is CSIS Security Group in?
CSIS Security Group's product category is Cybersecurity Services. Its primary akta.pro industry code is HDADAGAG, Managed Detection & Response (MDR) & SOC Services, with a secondary code of BPAHAEAG, Cybersecurity & Identity Consulting. Its NAICS code is 561621 and its SIC code is 7370.