Holm Security
A Stockholm-based vulnerability management platform offering unified scanning across network, cloud, web application, API, and human/phishing-simulation attack surfaces, backed by roughly €4-10M in disclosed funding.
Visit Website ↗ + Add to CompareOverview
Holm Security, founded in 2015 by Jens Larsson, Rickard Vikström, Victor Jerlin, and Stefan Thelberg, provides a next-generation vulnerability management platform designed to give organizations unified visibility and risk-based prioritization across a wide range of asset types — network infrastructure, cloud environments, web applications, APIs, and the human attack surface via phishing simulation — rather than requiring separate tools for each.
The company has raised disclosed funding including a €4M round from Subvenio Invest, positioning it as a smaller, European alternative to larger US-based vulnerability management vendors, with particular strength in Nordic and broader European mid-market customers who value data residency and a unified scanning approach.
Innovation Matrix Assessment
Continued expansion of scan coverage (network, cloud, web, API, phishing) over nearly a decade shows steady, if not exceptionally fast, iteration.
Unifying technical and human attack-surface testing in one platform genuinely reduces tool sprawl for security teams.
Modest disclosed funding (single-digit millions of euros) suggests real but limited growth capital relative to larger vulnerability management competitors.
Combining phishing simulation with technical vulnerability scanning in one platform is a useful consolidation, though each component builds on established scanning techniques.
Nearly a decade of operation and an established Nordic/European customer base is real-world evidence, though no independent efficacy benchmarks were found.
Unified technical and human vulnerability management remains a persistent need, particularly for European mid-market organizations prioritizing data residency.
Why CISOs Should Care
CISOs looking to consolidate network, cloud, web app, API, and phishing-simulation testing under one vendor — rather than stitching together several point scanners — get a single unified platform, with the added benefit of EU-based data handling for privacy-sensitive European customers.
What Makes It Different
Holm Security explicitly unifies technical vulnerability scanning with human-attack-surface testing (phishing simulation) in one platform and prioritizes European data residency, differentiating it from larger US vendors focused primarily on technical assets.
The Matrix Verdict
48/100 — EMERGING / UNRANKED
A solid, if modestly-funded, European vulnerability management vendor with genuine breadth across technical and human attack surfaces; real operational value for its target market, though smaller scale limits momentum and disruption relative to category leaders.
Editorial Note: Claims vs. Verified Findings
Funding figures vary between sources (€4M per ArcticStartup/FinSMEs vs. ~$9.88M per Crunchbase aggregation of multiple currencies/rounds); treat the total as approximate.
Sources
Alternatives to Holm Security
Unknown Cyber Inc.
CISO ReviewedMalware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
ReversingLabs
Software supply chain security and binary analysis vendor that inspects compiled software and packages for malware and unauthorized…