Sicra
Sicra is a Norwegian cybersecurity and IT infrastructure consultancy that serves enterprises (250+ employees) and public-sector organizations with Arctic Wolf-powered SOC MDR, security advisory, architecture, incident response, and NIS2/DORA/GDPR compliance services across the Nordics.
- Company typePrivate
- Founded2016
- HeadquartersKolbotn, Norway
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Sicra does
Sicra AS is a Norwegian cybersecurity and IT infrastructure competence house founded in September 2016 and headquartered in Oslo, with a registered address at Rosenholm Campus in Trollåsen. The company serves Norwegian enterprises of 250+ employees and public-sector organizations, organized around three service pillars: Security Advisory (consulting and risk assessment), Architecture and Transformation (IT modernization, cloud, and security design), and SOC / Security Operations (24/7 monitoring and incident response). Its flagship managed service is "Sicra SOC powered by Arctic Wolf," which protects over 50,000 end users with a stated average detection-to-case time of 7 minutes and 5 seconds, and is delivered as Sicra serves as the exclusive Norwegian contracting partner and Gold-level channel for Arctic Wolf, including being the only Norwegian member of the Arctic Wolf Advisory Council.
Sicra's broader product surface includes CISO-for-Hire, a dedicated Incident Response Team (IRT), response agreements with guaranteed 2/4/8-hour consultant access, penetration testing, cloud security across Azure/AWS/GCP, and regulatory compliance advisory for NIS2, DORA, GDPR, and ISO 27001. The platform layer is built on tight channel partnerships with Arctic Wolf, Palo Alto Networks (Prisma Cloud, Cortex, next-generation firewalls), Microsoft (M365, Defender, Sentinel, Azure), Zscaler, F5, Cisco, and Citrix, with Sicra holding elite partner tiers (Gold, Innovator, Solutions Partner, Delivery Partner). The firm is ISO 27001:2022 and ISO 9001:2015 certified and is led post-2025 by CEO Gaute Lien.
Commercially, Sicra operates a hybrid professional-services and managed-services model: project-based consulting, retainer-style response agreements, and recurring SOC MDR subscriptions. Pricing is quote-based and tailored to organization size, end-user count, and service level. The company is private, majority-owned (51%) since 2024 by Norwegian private equity firm Credo Partners AS, with original founders retaining equity; in the same year Sicra merged with Bluetree to pursue a leading Nordic cybersecurity position. Reported customer logos span BDO, Orkla Food Ingredients, Bertel O. Steen, Malling, Norwegian airline, Infinitum, Oslo Taxi, 28 Vestland municipalities (SYSIKT, IKT Nordhordland, IKT Nordfjord), FRID IKS, and Vestfold og Telemark County Municipality.
Sicra firmographics
Firmographics- Name
- Sicra
- Legal name
- Sicra AS
- Website
- https://sicra.no
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Sicra is a Norwegian cybersecurity and IT infrastructure consultancy that serves enterprises (250+ employees) and public-sector organizations with Arctic Wolf-powered SOC MDR, security advisory, architecture, incident response, and NIS2/DORA/GDPR compliance services across the Nordics.
- Ownership category
- akta.pro rank
Sicra industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Security Systems Services (56162), Computer Systems Design and Related Services (5415), Other Computer Related Services (541519)
- SIC
- Services-Services, Nec (8900), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG)
- akta.pro secondary industries
- Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC), OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN), Penetration Testing Platforms (PTaaS) (HDADAHAG)
Keywords
Where Sicra is headquartered
LocationHeadquarters
- HQ city
- Kolbotn
- HQ country
- Norway
- HQ region
- Europe
Offices3 records
Markets served
Sicra business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Cybersecurity Advisory and Consulting: Sicra provides tailored cybersecurity consulting services including security strategy, architecture, compliance (NIS2, DORA, GDPR, ISO27001), and CISO-for-hire engagements. Revenue is generated through project-based and retainer consulting agreements.
- SOC MDR Services (Arctic Wolf Partnership): Managed Detection and Response services delivered through the Arctic Wolf SOC-as-a-service platform. Sicra serves as the Norwegian contracting partner and local advisor. Pricing is tailored based on organization size, end-user count, and service level. Over 50,000 end users are protected by Sicra SOC powered by Arctic Wolf.
- Implementation and Integration Services: Design, implementation, and integration of security and network infrastructure platforms including Palo Alto Networks, Microsoft Azure, F5, Cisco, Zscaler, Citrix NetScaler, and Cato Networks. Revenue is generated through project-based implementation engagements.
- Response Agreements: Guaranteed access to consultants within 2 hours, 4 hours, or 8 hours for critical incidents. Includes 24/7/365 response time for Netscaler environments. These are retainer-style service agreements.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Tailored service agreements (quote-based) |
| Other | Multi-year contract | CISO-for-hire |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels7 records
Sicra product offering
Product offeringCore offering
Sicra is a Norwegian cybersecurity and IT infrastructure competence house that delivers tailored advisory, architecture, and managed security services. Its core offerings are organized into three service pillars: Security Advisory (consulting and risk assessments), Architecture and Transformation (IT and security modernization), and Security Operations (24/7 SOC monitoring and incident response powered by Arctic Wolf). Add-on services include CISO-for-Hire, Incident Response Team (IRT), penetration testing, cloud security, and regulatory compliance support for NIS2, DORA, and GDPR.
Product overview
Sicra is a Norwegian cybersecurity and IT infrastructure competence house that operates as a unified services portfolio rather than a single software product. The core offering is organized around three service pillars: Security Advisory (consulting and risk assessment), Architecture and Transformation (IT modernization and security design), and SOC / Security Operations (24/7 monitoring and incident response). The SOC service is powered by Arctic Wolf's platform. Additional add-on services include CISO-for-Hire (fractional security leadership), an Incident Response Team (IRT), penetration testing, cloud security across Azure/AWS/GCP, and regulatory compliance support for NIS2, DORA, and GDPR. Sicra also offers Response Agreements that guarantee consultant access within defined timeframes (2h/4h/8h). The company differentiates through deep certified expertise (GIAC, CISSP, Microsoft, Palo Alto Networks, Cisco, Citrix) and a local Norwegian presence combined with global security services.
Differentiator
Problem solved
Functional benefit
Brands
- Sicra SOC powered by Arctic Wolf: Security Operations Center services delivered in partnership with Arctic Wolf, providing 24/7 monitoring and incident management for clients.
- CISO for Hire
Products and services
- Sicra SOC (Security Operations Center) powered by Arctic Wolf Managed 24/7 Security Operations Center service for organizations that need continuous monitoring, threat detection, and incident response across IT and OT environments. Delivered as a managed service with Arctic Wolf's SOC-as-a-service platform, with Sicra acting as the Norwegian contracting partner and local advisor, and an average 7-minute-5-second detection-to-case response time.
- Security Advisory Advisory services helping clients understand and manage complexity in IT, infrastructure, and security. Delivered through structured assessments and analyses that produce a clear decision basis for risk reduction and business-value-driven prioritization. For IT directors, CISOs, and CIOs of mid-to-large Norwegian enterprises and public-sector organizations.
- Architecture and Transformation Planning, design, and execution of IT and security changes aligned with cloud, mobility, and compliance requirements. Produces robust solutions with better security, increased flexibility, and more efficient operations. Includes DevOps, Infrastructure-as-Code, Azure Key Vault, and NetScaler platform implementations.
- CISO-for-Hire Provides organizations with access to an experienced security leader on a part-time or project basis, offering strategic security leadership, compliance support (NSM, GDPR, ISO, NIS2), risk management, and advisory for management and boards without requiring a full-time CISO hire.
- Sicra Incident Response Team (IRT) A dedicated incident response team available to clients that have experienced a security breach, providing rapid expertise and coordination during and after incidents, including dialogue with Norwegian authorities (NSM, police).
- Response Agreement Retainer-style service agreement guaranteeing access to consultants within 2, 4, or 8 hours for critical incidents, with 24/7/365 response time coverage for NetScaler environments.
- Penetration Testing Security testing service that identifies vulnerabilities in client systems and infrastructure before malicious actors can exploit them, delivered as a standalone engagement for organizations needing to validate their security posture.
- Cloud Security Specialized services for securing cloud environments, including secure architecture and operations in Azure, AWS, and Google Cloud, covering identity management, data protection, and continuous monitoring.
- Regulatory Compliance Services (NIS2, DORA, GDPR) Services helping clients meet regulatory requirements including NIS2, DORA, and GDPR, through structured security analysis and compliance assessments, with ISO 27001 support.
Quantifiable outcome
- Average response time of 7 minutes and 5 seconds from detection to case creation in SOC monitoring
- +3 more outcomes
Companies that use Sicra
Customer profileNamed customers10 records
Segments5 records
Ideal customer profiles2 records
Sicra technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Sicra partnerships and signals
Strategic signalPartnerships
Twelve partnerships are on record, tiered flagship, core and minor.
- BluetreeflagshipSicra and Bluetree merged in 2024 to build a leading Nordic cybersecurity actor. Sicra formally acquired Bluetree through a combination of cash and shares in the new company. All key personnel continue as shareholders in the combined entity, strengthening IT and OT security capabilities across the Nordics.
- Thommessen (Law Firm)coreSicra and the law firm Thommessen entered into a strategic partnership on cybersecurity and compliance, combining legal expertise with cybersecurity advisory to serve clients with regulatory and compliance needs.
- Arctic WolfflagshipArctic Wolf offers SOC-as-a-service, with Sicra acting as Gold-level Norwegian contracting partner and local advisor. Sicra is the only Norwegian company in the Arctic Wolf Advisory Council. Over 50,000 end users are protected by Sicra SOC powered by Arctic Wolf. The partnership provides 24/7/365 monitoring with an average response time of 7 minutes 5 seconds.
- Palo Alto NetworkscoreSicra is Partner Level Innovator with Palo Alto Networks, offering next-generation firewalls, Prisma Cloud, and Cortex security automation. Sicra has Norway's most experienced team on Palo Alto's next-generation firewalls.
- MicrosoftcoreSicra is a Microsoft Solutions Partner – Security, specializing in Azure cloud services and Microsoft's security and identity portfolio (IAM). Deep expertise across all Microsoft security products including M365, Azure, Defender, and Sentinel.
- ZscalercoreSicra is a Zscaler Delivery Partner with Data Security Specialization. Authorized to design, implement, and operate the Zscaler platform for Zero Trust architecture, secure migration from traditional infrastructure, and cloud-based security for enterprise environments.
- F5 NetworkscoreSicra is an Authorized Level Partner for F5 Networks, specializing in F5 BIG-IP for application delivery, DDoS protection, web application security, API protection, and zero-trust security implementations.
- CiscocoreSicra is Cisco Preferred Networking Partner and Cisco Preferred Security Partner, with deep expertise across Cisco's networking and security portfolio including switching, routing, wireless, firewalls, and SD-WAN.
- Citrix (Cloud Software Group)coreSicra is a Silver Citrix Fusion Resell Partner and recognized as a strong expert environment on Citrix, particularly NetScaler's network products. The NetScaler team consists exclusively of senior consultants with extensive expertise.
- O3 Cyber (O3C)minorO3C specializes in public cloud security (Azure, AWS, GCP) while Sicra complements with on-premises and network expertise. Together they form tailored teams covering all customer needs, with O3C covering cloud security and Sicra covering hybrid environments.
- Norwegian Cyber Security ClusterminorSicra is a member of the Norwegian Cyber Security Cluster, a network focused on cybersecurity innovation and collaboration, enhancing knowledge sharing and industry development across Norway.
- Center for Internet Security (CIS)minorSicra is a CIS SecureSuite member, providing access to cybersecurity best practices and resources. Sicra actively works on configuration hardening for Entra ID, Active Directory, and various operating systems and applications.
Scale indicators5 records
Recent moves8 records
Expansion highlights6 records
Sicra competitors and assessment
Company assessmentDirect peers
- Atea: Atea is the largest Nordic IT infrastructure and services provider with a substantial cybersecurity practice. Highly comparable to Sicra in serving Nordic enterprises and municipalities with security advisory, network security, and managed services, though at much larger scale and broader portfolio.
- Tietoevry: Tietoevry is a leading Nordic IT services and software company with deep public-sector and financial services cybersecurity offerings. Comparable to Sicra in targeting Nordic enterprises with managed security, compliance advisory, and infrastructure modernization.
- Bouvet ASA: Bouvet is a Norwegian-headquartered IT consultancy with public-sector and enterprise focus. Comparable to Sicra in serving Norwegian clients with digital and security consulting, though Sicra is more deeply specialized in cyber and IT/OT security.
- Mnemonic AS: Mnemonic is a Norwegian-headquartered managed security services provider (MSSP) offering SOC, MDR, and incident response. Direct Norwegian competitor to Sicra SOC, with overlap in public-sector and enterprise security monitoring segments.
- DNV Cyber (formerly Nixu): DNV Cyber (incorporating Nixu) is a Nordic-origin cybersecurity firm providing managed security, advisory, and OT/industrial cybersecurity. Highly comparable to Sicra in IT/OT cybersecurity services across the Nordics, now backed by DNV.
- WithSecure (formerly F-Secure Business): WithSecure is a Finnish-headquartered cybersecurity vendor and managed services provider with Nordic enterprise and MSSP focus. Comparable to Sicra in delivering outcome-based managed security, though WithSecure owns more proprietary technology.
Broad incumbents
- Orange Cyberdefense: Orange Cyberdefense is the European MSSP arm of Orange, offering SOC/MDR, threat intelligence, and security consulting across Europe. A broader European incumbent comparable to Sicra's managed detection and response delivery model, with Norway presence via Basefarm acquisition.
- Sopra Steria: Sopra Steria is a large European IT services and consulting group with a cybersecurity practice serving public sector and regulated industries. Comparable to Sicra in Nordic enterprise/public-sector IT and security consulting at significantly larger scale.
- Devoteam: Devoteam is a European IT consultancy with a dedicated cybersecurity practice (Devoteam Cyber) covering managed services, cloud security, and compliance. Comparable to Sicra as a multi-vendor security integrator and managed security provider serving European enterprises.
- Capgemini Cybersecurity: Capgemini is a global IT services leader with a sizable Nordic presence and dedicated cybersecurity services covering managed detection, identity, OT, and compliance. Comparable to Sicra in enterprise security advisory and managed services though operating across much broader portfolios.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Sicra social profiles
Digital presenceSicra compliance and trust
Trust signalCompliance3 records
Sicra financial estimates
Financial estimateRevenue estimate
Valuation estimate
Sicra leadership team
Management profileNumber of profiles
Profiles5 records
Sicra subsidiaries and ownership
Company hierarchySubsidiaries1 record
Sicra funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Sicra M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Sicra
What does Sicra do?
Sicra is a Norwegian cybersecurity and IT infrastructure competence house that delivers tailored advisory, architecture, and managed security services. Its core offerings are organized into three service pillars: Security Advisory (consulting and risk assessments), Architecture and Transformation (IT and security modernization), and Security Operations (24/7 SOC monitoring and incident response powered by Arctic Wolf). Add-on services include CISO-for-Hire, Incident Response Team (IRT), penetration testing, cloud security, and regulatory compliance support for NIS2, DORA, and GDPR.
Is Sicra a public or private company?
Sicra is a private company. It is classified as private equity controlled and is currently operating.
When was Sicra founded?
Sicra was founded in 2016. It employs 11 to 50 people.
Where is Sicra based?
Sicra is headquartered in Kolbotn, Norway, in the Europe region.
How does Sicra make money?
Four revenue lines are on record. Cybersecurity Advisory and Consulting is the primary driver. The others are SOC MDR Services (Arctic Wolf Partnership), implementation and Integration Services and response Agreements.
Who are Sicra's main competitors?
Direct peers on record are Atea, Tietoevry, Bouvet ASA, Mnemonic AS, DNV Cyber (formerly Nixu) and WithSecure (formerly F-Secure Business). Broad incumbents are Orange Cyberdefense, Sopra Steria, Devoteam and Capgemini Cybersecurity.
Does Sicra have an API?
No public API is recorded for Sicra.
What industry is Sicra in?
Sicra's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEADAG, Network Security Managed Services (Firewall/IDS/IPS/SASE), with a secondary code of HDADAJAC, Critical Infrastructure Protection (CIP) & NERC-CIP Compliance. Its NAICS code is 56162 and its SIC code is 8900.