Skip to content
defend.gl

Cyber defence built for Greenland

Find the vulnerabilities before attackers do

We help Greenlandic businesses and public authorities test, find and close security gaps — through penetration testing, bug bounty and responsible vulnerability disclosure — with a clear, documented process from scoping to closed case.

We work to recognised standards and frameworks

  • OWASP Top 10
  • OWASP WSTG
  • PTES
  • NIST SP 800-115
  • CVSS
  • MITRE ATT&CK
  • CIS Controls
  • ISO/IEC 27001
  • NIS2
  • DORA
  • GDPR
  • Safe Harbor

Services

More ways to defend your organisation

From a one-off penetration test to ongoing bug bounty, responsible vulnerability disclosure, compliance advisory and security training — choose what fits where you are in your security journey.

Recommended service

Penetration testing

Structured attack simulation of your systems, carried out by experienced testers and documented in a report you can act on.

Read more

Bug bounty

Ongoing vulnerability testing carried out by a community of verified ethical hackers, with rewards for approved findings.

Read more

VDP

A secure, structured channel where security researchers can report vulnerabilities to you in a coordinated, responsible way, without legal uncertainty for either party.

Read more

Compliance

Practical help meeting NIS2, DORA, GDPR and ISO 27001 — your licence to operate, from gap analysis to documentation you can show.

Read more

Courses

Strengthen your team with practical security courses for employees and managers, in Danish and English.

Read more

Why

Proactive defence, before it becomes an incident

Cleaning up after an attack costs far more than closing a vulnerability. By finding the weaknesses yourselves — before anyone else does — you keep control of your own security posture.

  • Vulnerabilities are found and documented before they can be exploited.
  • You get a prioritised report — not just a list of technical findings.
  • A retest confirms that the fixes actually work.

The process

How we work

  1. Scope

    We map your systems together with you and agree scope, goals and rules of engagement before any testing begins.

  2. Test

    Our testers look for vulnerabilities — through penetration testing, bug bounty or responsible vulnerability disclosure, whichever fits you best.

  3. Report

    You get a prioritised report with concrete recommendations, walked through together with your team.

  4. Retest & close

    Once the vulnerabilities are fixed, we verify the fixes actually work and close the case.

In practice

From finding to closed vulnerability

This is how a vulnerability moves through the process — from the moment it is discovered to being reported, approved and closed.

  • Discovery – a vulnerability is identified and verified.
  • Reporting – the finding is documented with severity and impact.
  • Approval & closure – the fix is verified, and the case is closed.

Illustration of a security report, from discovering a vulnerability to an approved report and paid-out bounty.

defend.gl — hacker terminal Example

Illustrative example — not real figures.

The Community Fund

Security that benefits more people

The Community Fund is our initiative to make security testing accessible to Greenlandic organisations that don't have the budget for it themselves.

Learn about the Community Fund

Compliance

Are you covered by NIS2 or DORA?

More Greenlandic businesses and public authorities must now be able to document their security work. Our compliance advisory helps you turn the requirements into a concrete plan.

View compliance advisory
  • NIS2

    EU directive on network and information security for essential and important sectors.

  • DORA

    EU regulation on digital operational resilience in the financial sector.

  • GDPR

    Requirements for lawful and secure processing of personal data.

Ready to strengthen your defences?

Book a no-obligation meeting, or report a vulnerability if you've already found one.