ACE MATES was founded on a simple belief: Nordic organisations deserve a security partner that understands their threat landscape, their regulatory environment, their languages, and their way of working. We are that partner.
"Security is not a product you buy. It is a posture you build — with the right team, the right intelligence, and a partner who is as invested in your resilience as you are. ACE MATES exists to be that partner for every organisation in the Nordic region, regardless of size."
ACE MATES was founded in Stockholm in 2019 by two senior security analysts who had spent a decade working for global consultancies and noticed the same problem everywhere they went: Nordic organisations were receiving generic security advice designed for American or Western European threat models, delivered by consultants who didn't understand the local regulatory landscape and often didn't speak the language.
We started with a single client — a 200-person Swedish fintech — and a conviction that the right approach was to embed deeply, learn the business, and build a security programme from the inside out rather than parachuting in with a framework.
Five years later, ACE MATES protects over 340 organisations across Sweden, Norway, Denmark, Finland, and Iceland. We have grown from 2 to 48 specialists spanning offensive security, privacy law, cloud engineering, compliance, and threat intelligence — all with a Nordic-first mindset.
Two analysts, one client, one conviction: Nordic organisations deserved better.
Opened our 24/7 Security Operations Centre with Nordic-language analyst coverage.
Achieved ISO 27001 certification and opened Oslo and Copenhagen offices.
Expanded into Finland, launched GDPR practice, crossed 100 active clients.
Built dedicated regulatory compliance practice ahead of NIS2 transposition.
48 specialists across 5 countries. Recognised as a leading Nordic MSSP.
Six principles that govern every decision, every engagement, and every relationship we build with clients.
We publish our pricing. We tell clients when a finding is critical before the report is finished. We do not hide behind NDAs when we make mistakes. Transparency is the foundation of trust.
We work inside your organisation, not above it. We learn your systems, your team, your risk appetite. Our job is to be your security team — not a vendor you call once a year.
Our threat intelligence is Nordic-specific. Our regulatory advice reflects what IMY and Datatilsynet actually do. Our analysts speak your language. Not an afterthought — the core design principle.
We don't use junior analysts on client work. Every engagement is led by a certified senior practitioner with minimum five years experience in their domain. No exceptions.
Finding a vulnerability is the beginning, not the end. We stay through remediation, verify fixes, and don't consider an engagement complete until the client is materially safer than when we started.
Security is not a destination. We track our clients' maturity over time, celebrate improvements, and push for the next level. A static security programme is a degrading one.
Senior practitioners with real-world backgrounds in offensive security, privacy law, cloud engineering, and intelligence — not career consultants who learned security from a textbook.
Former red team lead at a Big Four firm. 14 years in offensive security across financial services and critical infrastructure. OSCP, CREST CRT.
Former headed Cyber for top nordics brands . Led ISO 27001 and SOC 2 programmes across 12 countries. Expert in NIS2, DORA, and Nordic regulatory strategy.
Privacy lawyer turned technologist. Former legal counsel at the Finnish DPA. GDPR enforcement experience from both sides of the table.
12 years in security operations. Built and led SOC teams at a Nordic telco and a global MSSP. Threat hunting, SIEM architecture, and incident response specialist.
Our founding office. Home to leadership, the SOC, and our largest team of 28 specialists covering all service lines.
Opened 2021. 10 specialists focused on Norwegian financial services, energy, and maritime sector clients.
Opened 2021. Serving Danish life sciences, shipping, and public sector clients with a team of 6 specialists.
Opened 2022. Finnish-language support across all services. 4 specialists with deep public sector expertise.
All client data processed and stored within EU jurisdiction. Native-language support in Swedish, Norwegian, Danish, and Finnish across all service lines.
Our team holds certifications from the most rigorous bodies in the industry. Every domain covered, every credential current.
We are technology-agnostic advisors who recommend what fits your environment — but we hold formal partnerships with the platforms we deploy most frequently.
The Stockholm-based MSSP reported 47% revenue growth in 2024, driven by NIS2 compliance demand and expanded SOC capacity.
Norwegian businesses sought Nordic-language security partners following a wave of ransomware attacks targeting Scandinavian SMEs in Q3 2024.
The expansion reflects increasing regulatory pressure on Danish organisations ahead of the November 2024 NIS2 implementation deadline.
Finnish language security capabilities now available through ACE MATES Helsinki, covering GDPR, NIS2, and managed SOC for Finnish organisations.
Book a free 90-minute threat briefing. We'll show you exactly where you stand — and what it takes to get to where you want to be.