UNITAS

UNITAS

Speciality: Network Security

Aarhus, Denmark 21 employees
[01] About

IT Services and IT Consulting firm specializing in information security, IT security, GRC/compliance, and IT auditing; offers penetration testing via pentest-as-a-service, vulnerability scanning, and exploitability assessments; 13 employees, founded 2019, headquartered in Aarhus, Denmark.

UNITAS provides advisory services on information security, IT security, GRC/compliance, and IT auditing. ISO27001/2 - ISO27005 - CIS Controls – GDPR – NIS2 – DORA – Vulnerability scanning We offer a range of services within GDPR, as well as roles such as DPO, CISO, and information security consultant. We take care of the work, ensuring that you align with both regulatory and internal requirements for compliance and information security. Risk management, strategies, processes, standards, workflows, technical measures, leadership training, IT contingency plans, annual cycles, and audit reports all resonate with UNITAS. We work within various regulatory frameworks, including, for example, but not exclusively, GDPR, NIS 2, and DORA. Our work is primarily structured according to ISO standards. Our clients span across different sectors beyond the public sector, including, for instance, healthcare, finance, aviation, utilities, manufacturing, distribution/logistics, and marketing. Furthermore, we provide guidance to a wide range of IT vendors, including hosting providers. Some of our clients operate in multiple EU countries. Additionally, some clients have significant operations outside of the EU. UNITAS is known for being a versatile workshop. We can deliver at both high and low levels, from management to practical implementation. Read more on our website.
[02] Services
Vciso Service Agreement
GDPR Service Agreement
NIS 2 Implementation
CIS-18 Cybersecurity Best Practices
Vulnerability Scanning
Penetration Testing
[03] Certifications
ISO 27001/2
ISO 27005
CIS Controls
GDPR

GDPR Certification Overview


Origin


The General Data Protection Regulation (GDPR) was created by the European Union and came into effect on May 25, 2018. It was developed by the European Parliament and Council to modernize and unify data protection laws across all EU member states. The regulation was created in response to the rapid growth of digital technology and data processing, aiming to give individuals greater control over their personal data while establishing clear obligations for organizations that collect, store, and process such information.


Industry Value


GDPR compliance is highly valued in the industry because it demonstrates an organization's commitment to data privacy and security, which has become a critical business concern globally. Organizations with GDPR expertise can avoid substantial fines (up to €20 million or 4% of annual global turnover), maintain customer trust, and gain competitive advantages when doing business with European entities or handling EU citizens' data. Professionals with GDPR certification are in high demand as companies worldwide seek to ensure compliance, implement proper data protection frameworks, and avoid the legal, financial, and reputational risks associated with data breaches and non-compliance.

NIS2

NIS2 Directive Overview


Origin and Background


The NIS2 Directive (Network and Information Security Directive 2) was created by the European Union and adopted in January 2023, replacing the original NIS Directive from 2016. The European Parliament and Council developed this legislation to address the growing cybersecurity threats across member states and to create a more uniform approach to cybersecurity requirements. It was implemented because the original directive had inconsistent application across EU countries and didn't adequately cover the expanding digital landscape and supply chain vulnerabilities that emerged in recent years.


Industry Importance and Value


NIS2 is significant because it establishes mandatory cybersecurity requirements for approximately 160,000 organizations across essential and important sectors in the EU, including energy, healthcare, banking, digital infrastructure, and public administration. The directive is valued for creating harmonized cybersecurity standards across Europe, improving incident reporting mechanisms, and holding senior management directly accountable for compliance. For organizations doing business in or with the EU, NIS2 compliance has become essential—not only to avoid substantial penalties (up to €10 million or 2% of global turnover) but also to demonstrate robust cybersecurity practices to partners and customers in an increasingly interconnected global market.

DORA

DORA (Digital Operational Resilience Act)


DORA is a regulatory framework created by the European Union that entered into force in January 2023, with full application required by January 2025. Developed by the European Commission, the European Parliament, and the Council of the European Union, DORA was established to strengthen the digital operational resilience of financial entities across the EU. The regulation emerged from growing concerns about cyber threats, ICT disruptions, and third-party dependencies that could destabilize the financial sector, particularly following increased digitalization and cloud adoption in financial services.


DORA is highly valued in the penetration testing and cybersecurity industry because it mandates comprehensive testing requirements for financial institutions, including advanced threat-led penetration testing (TLPT) for critical entities. Penetration testing companies reference DORA compliance as it creates significant demand for their services—financial organizations must conduct regular security testing, vulnerability assessments, and sophisticated red team exercises to meet regulatory obligations. For cybersecurity firms, demonstrating knowledge of DORA requirements and offering DORA-aligned testing services has become a competitive differentiator, as it shows they understand the specific regulatory landscape their financial sector clients must navigate and can deliver testing programs that meet these stringent EU standards.