Who We Are

Security built
for the Nordics

ACE MATES was founded on a simple belief: Nordic organisations deserve a security partner that understands their threat landscape, their regulatory environment, their languages, and their way of working. We are that partner.

Work With Us → See Our Work
Our Belief

"Security is not a product you buy. It is a posture you build — with the right team, the right intelligence, and a partner who is as invested in your resilience as you are. ACE MATES exists to be that partner for every organisation in the Nordic region, regardless of size."

— The ACE MATES Founding Team, Stockholm, 2019
2019Founded
0Clients Protected
0Team Members
0Nordic Countries
0Threats Blocked / Year

From two analysts
to the Nordic region's
most trusted MSSP

ACE MATES was founded in Stockholm in 2019 by two senior security analysts who had spent a decade working for global consultancies and noticed the same problem everywhere they went: Nordic organisations were receiving generic security advice designed for American or Western European threat models, delivered by consultants who didn't understand the local regulatory landscape and often didn't speak the language.

We started with a single client — a 200-person Swedish fintech — and a conviction that the right approach was to embed deeply, learn the business, and build a security programme from the inside out rather than parachuting in with a framework.

Five years later, ACE MATES protects over 340 organisations across Sweden, Norway, Denmark, Finland, and Iceland. We have grown from 2 to 48 specialists spanning offensive security, privacy law, cloud engineering, compliance, and threat intelligence — all with a Nordic-first mindset.

2019

Founded in Stockholm

Two analysts, one client, one conviction: Nordic organisations deserved better.

2020

SOC launched

Opened our 24/7 Security Operations Centre with Nordic-language analyst coverage.

2021

ISO 27001 certified

Achieved ISO 27001 certification and opened Oslo and Copenhagen offices.

2022

100 clients reached

Expanded into Finland, launched GDPR practice, crossed 100 active clients.

2023

NIS2 & DORA practice

Built dedicated regulatory compliance practice ahead of NIS2 transposition.

2024

340+ clients

48 specialists across 5 countries. Recognised as a leading Nordic MSSP.

Our Values

Six principles that govern every decision, every engagement, and every relationship we build with clients.

01
Transparency First

We publish our pricing. We tell clients when a finding is critical before the report is finished. We do not hide behind NDAs when we make mistakes. Transparency is the foundation of trust.

02
Embedded, Not Parachuted

We work inside your organisation, not above it. We learn your systems, your team, your risk appetite. Our job is to be your security team — not a vendor you call once a year.

03
Nordic by Design

Our threat intelligence is Nordic-specific. Our regulatory advice reflects what IMY and Datatilsynet actually do. Our analysts speak your language. Not an afterthought — the core design principle.

04
Senior Eyes on Every Engagement

We don't use junior analysts on client work. Every engagement is led by a certified senior practitioner with minimum five years experience in their domain. No exceptions.

05
Fix It, Don't Just Find It

Finding a vulnerability is the beginning, not the end. We stay through remediation, verify fixes, and don't consider an engagement complete until the client is materially safer than when we started.

06
Continuous Improvement

Security is not a destination. We track our clients' maturity over time, celebrate improvements, and push for the next level. A static security programme is a degrading one.

Leadership

Senior practitioners with real-world backgrounds in offensive security, privacy law, cloud engineering, and intelligence — not career consultants who learned security from a textbook.

EL
Amit Sharma
CEO & Co-Founder

Former red team lead at a Big Four firm. 14 years in offensive security across financial services and critical infrastructure. OSCP, CREST CRT.

OSCPCREST CRTCEH
AH
Santosh C
COO & Co-Founder

Former headed Cyber for top nordics brands . Led ISO 27001 and SOC 2 programmes across 12 countries. Expert in NIS2, DORA, and Nordic regulatory strategy.

CISAISO LACISM
MK
Mia Korhonen
Head of Privacy & Compliance

Privacy lawyer turned technologist. Former legal counsel at the Finnish DPA. GDPR enforcement experience from both sides of the table.

CIPP/ECIPMFIP
JR
Jonas Rasmussen
Head of SOC

12 years in security operations. Built and led SOC teams at a Nordic telco and a global MSSP. Threat hunting, SIEM architecture, and incident response specialist.

GCTIGCIAGCIH

Offices Across
the Nordic Region

🇸🇪
Stockholm
Sweden — HQ

Our founding office. Home to leadership, the SOC, and our largest team of 28 specialists covering all service lines.

🇳🇴
Oslo
Norway

Opened 2021. 10 specialists focused on Norwegian financial services, energy, and maritime sector clients.

🇩🇰
Copenhagen
Denmark

Opened 2021. Serving Danish life sciences, shipping, and public sector clients with a team of 6 specialists.

🇫🇮
Helsinki
Finland

Opened 2022. Finnish-language support across all services. 4 specialists with deep public sector expertise.

Service Coverage by Country
🇸🇪 Sweden
🇳🇴 Norway
🇩🇰 Denmark
🇫🇮 Finland
🇮🇸 Iceland

All client data processed and stored within EU jurisdiction. Native-language support in Swedish, Norwegian, Danish, and Finnish across all service lines.

Certifications & Accreditations

Our team holds certifications from the most rigorous bodies in the industry. Every domain covered, every credential current.

OSCPOffensive Security Certified Professional6 certified analysts
CRESTCouncil for Registered Ethical Security Testers4 CRT certified
CIPP/ECertified Information Privacy Professional / Europe5 certified
CISACertified Information Systems Auditor4 certified
ISO 27001ISO/IEC 27001 Lead Auditor (PECB)Organisationally certified
AWS SAPAWS Certified Security Specialty3 certified engineers
AZ-500Microsoft Azure Security Technologies3 certified engineers
GCTIGIAC Cyber Threat Intelligence4 certified analysts

Our Technology Stack

We are technology-agnostic advisors who recommend what fits your environment — but we hold formal partnerships with the platforms we deploy most frequently.

🔵MicrosoftGold Security Partner
🟠AWSSecurity Competency
🟣CrowdStrikeAuthorised Reseller
🟢SnykTechnology Partner
🔴TenableAuthorised Partner
🟦VantaImplementation Partner
Palo AltoNextWave Partner
🟡SplunkAuthorised Partner

In the News

Mar 2025Computer Sweden
"ACE MATES ranked among Sweden's fastest-growing security companies for the third consecutive year"

The Stockholm-based MSSP reported 47% revenue growth in 2024, driven by NIS2 compliance demand and expanded SOC capacity.

Nov 2024Dagens Næringsliv
"Norsk sektor vender seg til nordisk sikkerhetsspesialist etter bølge av løsepengevirus"

Norwegian businesses sought Nordic-language security partners following a wave of ransomware attacks targeting Scandinavian SMEs in Q3 2024.

Jun 2024IT-Branchen DK
"ACE MATES opens Copenhagen office to serve growing Danish demand for NIS2 readiness"

The expansion reflects increasing regulatory pressure on Danish organisations ahead of the November 2024 NIS2 implementation deadline.

Jan 2024Tivi.fi
"Kyberturvallisuus nousee suomalaisten yritysten prioriteettilistalle — ACE MATES laajentaa Helsinkiin"

Finnish language security capabilities now available through ACE MATES Helsinki, covering GDPR, NIS2, and managed SOC for Finnish organisations.

Join 340+ Nordic Organisations

Ready to Work With Us?

Book a free 90-minute threat briefing. We'll show you exactly where you stand — and what it takes to get to where you want to be.