Applied Risk
- Company typePrivate
- Founded2012
- HeadquartersAmsterdam, Netherlands
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Applied Risk does
Applied Risk is a Netherlands-based cybersecurity firm founded in 2012 in Amsterdam by Jalal Bouhdada, focused on protecting critical infrastructure operators from cyber threats that could compromise safety, operations, and intellectual property. Following its acquisition by DNV, the company operates as part of DNV Cyber, a global unit combining 500+ cybersecurity experts with 30 years of IT and OT security experience serving maritime, energy, manufacturing, healthcare, and national security clients. Its service portfolio is structured around three phases — govern, prepare & prevent, and detect & respond — and includes governance consulting, threat detection, incident response, certification, and managed security services delivered through enterprise field sales engagements on a quote-based pricing model.
Applied Risk firmographics
Firmographics- Name
- Applied Risk
- Website
- https://applied-risk.com
- Company type
- Private
- Founded year
- 2012
- Headcount range
- 1–10 employees
- Ownership category
- akta.pro rank
Applied Risk industry classification
Industry- Product category
- Industrial Cybersecurity Services
- NAICS
- Investigation and Security Services (5616)
- SIC
- Services-Engineering, Accounting, Research, Management (8700), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Security Incident Response (IR) & Digital Forensics Services (BPAEADAI)
- akta.pro secondary industries
- Threat Intelligence Services (BPAEADAC), Maritime Security Risk Assessments & Audits (BPAKALAF), Security Consulting, Risk Assessment & Security Program Design (BPABAMAE)
Keywords
Where Applied Risk is headquartered
LocationHeadquarters
- HQ city
- Amsterdam
- HQ country
- Netherlands
- HQ region
- Europe
Offices1 record
Markets served
Applied Risk business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Cybersecurity Services: DNV Cyber generates revenue through professional cybersecurity services including governance consulting, threat detection, incident response, certification, and managed security services. They provide expert consultation across IT and OT security domains for organizations with complex, regulated environments.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels5 records
Applied Risk product offering
Product offeringCore offering
Applied Risk is a cybersecurity firm focused on critical infrastructure security, helping industrial organizations combat security breaches in IT and operational technology (OT) environments. Following its acquisition by DNV Cyber, the combined offering covers three service pillars — Govern (cybersecurity strategy, processes, policies and certification), Prepare & Prevent (asset/data protection, security controls, vulnerability management), and Detect & Respond (24/7 monitoring, threat detection, and incident response) — delivered to enterprises in maritime, energy, manufacturing, healthcare, and national security sectors.
Differentiator
Problem solved
Functional benefit
Products and services
- Govern
Quantifiable outcome
- Organizations gain structured approach to NIS2 Directive compliance through three-step methodology
Companies that use Applied Risk
Customer profileSegments5 records
Ideal customer profiles5 records
Applied Risk technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Applied Risk partnerships and signals
Strategic signalScale indicators3 records
Recent moves3 records
Expansion highlights5 records
Applied Risk competitors and assessment
Company assessmentBroad incumbents
- CrowdStrike: Leading endpoint and cloud-native security vendor with a growing OT security practice. A broad incumbent whose MSSP-grade services and Falcon platform increasingly overlap with Applied Risk's detection-and-response stack.
- Palo Alto Networks (Unit 42): Global cybersecurity platform whose Unit 42 consulting arm delivers IR, threat intelligence, and risk assessment services. Comparable as a large incumbent competing for enterprise OT/IT advisory and managed security work.
Direct peers
- Mandiant (Google Cloud): Global incident response, threat intelligence, and managed detection firm now part of Google Cloud. Direct competitor for IR retainers and high-end OT/IT consulting engagements Applied Risk pursues.
- Claroty: Industrial cybersecurity platform protecting OT, IoT, and IIoT environments in manufacturing, energy, and healthcare. Competes head-to-head for OT visibility and asset protection mandates alongside Applied Risk's services.
- Dragos: OT cybersecurity specialist focused on industrial asset operators in power, water, and manufacturing. Directly comparable to Applied Risk's OT security and incident response practice in critical infrastructure.
- NCC Group: UK-headquartered cyber security and resilience consultancy offering advisory, testing, and managed detection services. Closely comparable services-led model to Applied Risk, including critical infrastructure and regulated-industry work.
- Nozomi Networks: OT and IoT security vendor specializing in network visibility, threat detection, and vulnerability management for critical infrastructure operators. Overlaps with Applied Risk's ICS monitoring and threat intelligence offerings.
- IOActive: Specialist security services firm offering penetration testing, ICS/SCADA assessments, and hardware security research for industrial and embedded systems. Comparable niche services to Applied Risk's critical infrastructure assurance work.
- TÜV Rheinland Cybersecurity: Testing, inspection, and certification body with industrial cybersecurity advisory and certification services. Closely mirrors Applied Risk's combination of inspection-body credibility and OT cyber advisory.
Emerging players
- Forescout: Cybersecurity platform focused on connected device visibility and OT/IoT exposure management. Competes for asset discovery and continuous monitoring budgets overlapping with Applied Risk's managed services.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Applied Risk social profiles
Digital presenceApplied Risk financial estimates
Financial estimateRevenue estimate
Valuation estimate
Applied Risk leadership team
Management profileNumber of profiles
Profiles1 record
Applied Risk funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Applied Risk M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Applied Risk
What does Applied Risk do?
Applied Risk is a cybersecurity firm focused on critical infrastructure security, helping industrial organizations combat security breaches in IT and operational technology (OT) environments. Following its acquisition by DNV Cyber, the combined offering covers three service pillars — Govern (cybersecurity strategy, processes, policies and certification), Prepare & Prevent (asset/data protection, security controls, vulnerability management), and Detect & Respond (24/7 monitoring, threat detection, and incident response) — delivered to enterprises in maritime, energy, manufacturing, healthcare, and national security sectors.
When was Applied Risk founded?
Applied Risk was founded in 2012. It employs 1 to 10 people.
Where is Applied Risk based?
Applied Risk is headquartered in Amsterdam, Netherlands, in the Europe region.
How does Applied Risk make money?
One revenue line is on record: cybersecurity Services.
Who are Applied Risk's main competitors?
Broad incumbents on record are CrowdStrike and Palo Alto Networks (Unit 42). Direct peers are Mandiant (Google Cloud), Claroty, Dragos, NCC Group, Nozomi Networks, IOActive and TÜV Rheinland Cybersecurity. Forescout is listed as an emerging player.
Does Applied Risk have an API?
No public API is recorded for Applied Risk.
What industry is Applied Risk in?
Applied Risk's product category is Industrial Cybersecurity Services. Its primary akta.pro industry code is BPAEADAI, Security Incident Response (IR) & Digital Forensics Services, with a secondary code of BPAEADAC, Threat Intelligence Services. Its NAICS code is 5616 and its SIC code is 8700.