Sectors
Each sector has its own supervisor, its own law and its own place where cloud and AI hurt.
We have worked in all three. Here your supervisor and your estate are named, because that is where the generic pages stop.
01
Energy
- The law
- NIS2 under Act no. 258 of 6 March 2025 for the energy sector; a sector act with its own deadlines and its own incident reporting.
- The supervisor
- The Danish Energy Agency, with incidents reported to CFCS.
- The estate
- Trading and utility estates: millions of meter readings a day, HES and MDM, DataHub 3.0 on its way, 15-minute settlement, flexibility markets, OT environments with their own rules for who may reach what.
- What has set it off
- A NIS2 audit date, a vendor review from Energinet or the grid company, or an AI pilot that may not move meter data out of the country.
- The AI case
- Forecasting and agents in operations: fault handling, customer enquiries, balancing. Built on event streams of meter data, on infrastructure you control.
- We have worked for
- Norlys, Sinal, N1, OK, Energinet
02
Finance
- The law
- DORA, Regulation (EU) 2022/2554, in force since 17 January 2025, for banks, payment companies and their critical IT suppliers.
- The supervisor
- The Danish FSA, Finanstilsynet.
- The estate
- Core banking and payments on a mix of mainframe, private cloud and a hyperscaler. Instant payments and Verification of Payee since October 2025, ISO 20022, PSD3 and FiDA ahead. Third-party risk and exit plans as supervisory requirements, not good intentions.
- What has set it off
- The DORA audit that asks for a tested exit plan from the cloud provider. A renewal with the hyperscaler. An AI strategy that compliance has to approve.
- The AI case
- Agents in case handling and customer contact, with traceability that can be produced. A crypto inventory and a roadmap towards post-quantum cryptography before the supervisor asks for it.
- We have worked for
- Danske Bank, Danske Commodities, VaaS.Digital
03
Hospitality
- The law
- GDPR at scale: guest data across countries, payment data, and the EUDI wallet as identity by the end of 2026.
- The supervisor
- The Danish Data Protection Agency, and your payment provider’s requirements.
- The estate
- Hotel systems, payments, guest identity and mobile check-in across chains and countries, often built by a tech supplier that itself has to pass the hotel chain’s vendor review.
- What has set it off
- A hotel chain asking where the guests’ data lives. The EUDI wallet changing what identity is. An AI feature that has to be built into the product without moving data to the US.
- The AI case
- AI‑native product development for a hotel-tech company: agents that handle the guest’s journey from booking to check-out, on European infrastructure.
- We have worked for
- AeroGuest, founded by Martin
No other Danish consultancy names hospitality. We have built a platform in that sector from the ground up.