Cybersecurity expert · former CISO and CTO · CEO at Sekuritet

Martin Stoltenberg Potestas

Martin helps boards, executive teams and IT leaders understand, prioritise and document cyber risk — from the engine room to the boardroom.

He combines more than 25 years in IT with leadership, running companies and board work. The approach is simple: documentation over assumptions. Security that works in practice.

Portræt af Martin Stoltenberg Potestas

At a glance

Role
CEO and founder, Sekuritet — independent IT security advisory in Denmark
Experience
More than 25 years in IT and 15 years with cybersecurity as the primary focus — as CISO, CTO, senior architect and company founder
Public appointment
Appointed external examiner in IT security and IT development, 2025–2029: designated to assess exams at Danish higher-education IT programmes
Leadership & board
Experience as CEO, CTO, company founder and chairman of the board · today chairman of the residents’ board at Nørrevang and member of the board of the housing association Herlev Boligselskab · member of the Danish Board Association (Bestyrelsesforeningen) · CBS Executive board director programme · Harvard Business School, Certificate of Specialization in Leadership and Management · AP degree in leadership and management
Security & governance
CISSP, CCSP, CISM, CISA, CRISC · ISO/IEC 27001 Senior Lead Implementer and Senior Lead Auditor, i.e. certified both to build and to audit security · NIS2 Directive Senior Lead Implementer · ISO/IEC 27005 Senior Lead Risk Manager
Offensive security & incident response
GPEN, GCIH and GSEC · GIAC Advisory Board (by invitation after a top score on a GIAC exam) · Certified Ethical Hacker · Lead Pen Test Professional · ISO/IEC 27035 Senior Lead Incident Manager
Cloud & Microsoft
CCSP and Senior Lead Cloud Security Manager · Microsoft 365 Enterprise Administrator Expert, Azure Administrator and Windows Server Hybrid · 26 Microsoft certifications in total
Focus areas
Cyber risk and governance · advising boards and executive teams · CISO Service · penetration testing, Assume Breach and offensive security · security assessments of Microsoft 365 and Active Directory · identity and access management · cloud and hybrid environments · supplier and third-party risk · NIS 2, ISO 27001 and risk management · security awareness · AI governance · preparedness and incident response
Languages
Danish (native), English (professional)

Good cybersecurity is not about implementing as much as possible. It is about understanding the risk, prioritising correctly and being able to document that the chosen security measures work.

Martin Stoltenberg Potestas

How Martin works

Martin is direct in his assessments but respectful of the people who carry the responsibility. He makes complex problems understandable, says clearly when something cannot yet be concluded, and does not recommend more security than the risk requires.

01

Documentation before conclusions

Analyses that can be checked, and reports management can act on.

02

Plain language without unnecessary drama

What is documented, what is likely and what we do not yet know are kept clearly apart.

03

Recommendations that work in real operations

Prioritised by risk, impact and practical feasibility — not theoretical perfection.

Where Martin can contribute

Four routes in, depending on whether you are looking for advice for your organisation, are a journalist or an organiser, or carry the responsibility in an executive team or board.

For companies and IT leaders

Independent advice and concrete engagements through Sekuritet. The first step is always a free pre-analysis with a fixed price:

Sekuritet verifies your security. We do not run your IT.

For the media

Need an expert assessment? Martin comments on, among other things:

  • current cyberattacks and data breaches
  • ransomware and digital extortion
  • NIS 2 and management responsibility
  • attacks on Microsoft 365, identity environments and Active Directory
  • preparedness, backup and recovery
  • boards’ responsibility for cyber risk
  • education and the cybersecurity skills gap

Martin distinguishes clearly between what is documented, what is likely and what we do not yet know.

Press enquiries: call directly on +45 30 96 31 31 or write to martin@sekuritet.com.

Latest appearance: The Sidechannel on insecure mail servers in Denmark (21 September 2026)

Talks and panel debates

Book Martin for a keynote, panel debate or expert briefing. Possible topics:

  • Cybersecurity from the engine room to the boardroom
  • Documented security instead of assumptions
  • What should the board actually ask?
  • When the cyber response plan meets reality
  • NIS 2 without compliance theatre

Advisory and board work

Strategic sparring on cyber risk and digital resilience. Martin has six years of experience as chairman of the board and today serves on boards in the Danish non-profit housing sector. His particular contribution in the boardroom is making complex technology and cyber risks concrete enough for the board to prioritise, oversee and decide. He contributes especially within:

  • cyber and technology risk
  • digital resilience and preparedness
  • management reporting and controls
  • critical supplier dependencies
  • technology and security strategy
  • AI governance and information protection

Press biography for free use

Both texts may be used freely. A portrait is available on request.

Short (for a byline or fact box)

Martin Stoltenberg Potestas is a cybersecurity expert, CEO and founder of Sekuritet, and a former CISO and CTO. He has more than 25 years in IT and began specialising in cybersecurity in 2011. He holds the CISSP, CISM, CISA and GPEN certifications, among others, and is an appointed external examiner in IT security and IT development for 2025–2029.

Long (for a profile or programme)

Martin Stoltenberg Potestas is a cybersecurity expert, CEO and founder of Sekuritet, an independent IT security advisory in Denmark. He has more than 25 years in IT infrastructure as infrastructure architect, CTO and CISO, began specialising in cybersecurity in 2011 and has founded several companies. He advises boards, executive teams and IT leaders on cyber risk, from the engine room to the boardroom, and holds the CISSP, CCSP, CISM, CISA, CRISC, GPEN and GCIH certifications among others. He has completed Stanford’s Advanced Cybersecurity Program, Harvard Business School’s Certificate of Specialization in Leadership and Management and CBS Executive’s board director programme, and is an appointed external examiner in IT security and IT development for 2025–2029.

In the media

Martin contributes as an expert source on current cyber threats, security incidents and the management consequences of technical risk.

Own analyses and articles

Martin’s own analyses and professional perspectives, written for decision-makers in Danish: technical understanding, a management perspective and a clear thesis.

Clients on working with Sekuritet

Sekuritet has advised, among others, Unilite, Cadpeople, Kunde & Co and Bitcoin Suisse.

»The assessment we received deserves a 10 out of 10 without hesitation.«

Ionela Dumitrescu · Production Manager, responsible for IT and Digitalisation · Unilite A/S

»Sekuritet challenged that decision and recommended starting with a security assessment instead. It turned out to be the right call.«

Nikolaj Have · Partner, CTO & Board Member · Cadpeople A/S

More client testimonials →

Experience

Current

  1. 2022–CEO and founder, SekuritetPrimary role.
  2. 2025–Appointed external examiner in IT security and IT development (2025–2029)
  3. 2026–Co-founder and CEO, Governance Privacy IntelligenceSecure and controlled use of AI in organisations: AI governance and controlled access to language models.
  4. 2020–Founder, Amplus ApS
  5. Chairman, residents’ board at Nørrevang, Herlev Boligselskab
  6. Board member, Herlev Boligselskab
  7. Member, Danish Board Association (Bestyrelsesforeningen)

Previous

  1. Chairman and vice-chairman, Round Table 60 Herlev
  2. 2018–2022Co-founder and managing partner, Sipato
  3. 2016–2022Chairman of the board, Sipato
  4. 2015–2018CISO, Progressive A/S
  5. 2015CTO, Systemhosting A/S
  6. 2011–2015Senior architect and technical lead, Progressive A/S
  7. 2007–2011Infrastructure architect, Cortex Consult A/S
  8. 2003–2007Founder, IceSystems
  9. 2000–2003IT consultant, Colberghus

Education

  1. 2025Stanford School of Engineering / Stanford Online – Advanced Cybersecurity ProgramStanford’s technical deep-dive in cybersecurity: how cryptography fails in practice, how secure code is written, and how web and network attacks work and are defended against. It is the technical foundation beneath the advice: Martin can verify what a vendor claims instead of taking it on trust. Five courses: Foundations of Information Security, Using Cryptography Correctly, Writing Secure Code, Web Security and Network Security.
  2. 2023–2024CBS Executive – Board director programme (Bestyrelsesuddannelsen)Denmark’s most established board director programme, developed by CBS with EY and Kromann Reumert. A 360-degree view of board work: the board’s legal responsibilities, accounts and capital, strategy and value creation, the interplay between board and management, and digitalisation and cybersecurity as a board topic. The exam is run as a board meeting. For Martin it is the bridge between technology and the boardroom: he knows the frameworks cyber risk must be translated into before a board can act on it.
  3. 2021–2022Harvard Business School – Certificate of Specialization in Leadership and ManagementHarvard Business School’s leadership courses taught by the case method: real dilemmas from real companies, where participants must make and defend decisions as leaders do. The specialization covers leading people, organisations and change. For Martin it is the leadership side of being a CISO and CEO: making security happen in an organisation, not just on paper.
  4. 2021CBS Executive – Economic Management and Strategic DevelopmentExecutive programme in financial management and strategic development.
  5. 2011–2017Copenhagen Business Academy – AP Degree in Leadership and ManagementHigher education in leadership completed part-time alongside work: leadership in practice, organisation and strategic leadership.
  6. 2009–2010IT University of Copenhagen – IT Project ManagementIT project management at university level.
  7. Business Academy Aarhus – Diploma in IT securityDiploma programme in IT security at bachelor level.

Certifications

Martin’s certifications span cyber governance and audit, penetration testing, incident response, cloud, Microsoft and classic infrastructure. The most important:

  • CISSP
  • CCSP
  • CISM
  • CISA
  • CRISC
  • GPEN
  • GCIH
  • ISO/IEC 27001 Senior Lead Implementer and Senior Lead Auditor
  • NIS2 Directive Senior Lead Implementer
  • Microsoft 365 Enterprise Administrator Expert

80+ certifications and completed specialist courses

See 70 selected certifications and specialist courses

Security, audit & governance

  • CISSP (ISC2)
  • CCSP (ISC2)
  • SSCP (ISC2)
  • CISM (ISACA)
  • CISA (ISACA)
  • CRISC (ISACA)
  • NIS2 Directive Senior Lead Implementer (PECB)
  • ISO/IEC 27001 Senior Lead Implementer (PECB)
  • ISO/IEC 27001 Senior Lead Auditor (PECB)
  • ISO/IEC 27005 Senior Lead Risk Manager (PECB)
  • ISO/IEC 27035 Senior Lead Incident Manager (PECB)
  • Senior Lead Cybersecurity Manager (PECB)
  • Senior Lead Cloud Security Manager (PECB)

Offensive security & incident response

  • GIAC Penetration Tester (GPEN)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Security Essentials (GSEC)
  • GIAC Advisory Board
  • Lead Pen Test Professional (PECB)
  • Certified Ethical Hacker (CEH)
  • CIW Web Security Professional

Microsoft 365, Azure & Windows Server

  • Microsoft 365 Enterprise Administrator Expert
  • Microsoft 365 Modern Desktop Administrator
  • Microsoft 365 Messaging Administrator
  • Azure Administrator (AZ-104)
  • Windows Server Hybrid (AZ-801)
  • MS-100 Identity
  • MS-101 Security
  • MCSE Productivity
  • MCSE Messaging
  • MCSE Cloud Platform
  • MCSA Windows Server 2016
  • MCSA Windows Server 2012
  • MCSA Windows Server 2008
  • MCSA Windows 10
  • MCITP Enterprise Administrator
  • MCITP Server Administrator
  • MCITP Enterprise Messaging
  • MCTS Active Directory 2008
  • MCTS Network 2008
  • MCTS Applications 2008
  • MCTS Exchange 2010
  • Microsoft Specialist Exchange 2016
  • Microsoft Specialist Office 365
  • Microsoft Specialist Hyper-V
  • Microsoft Specialist Windows 7
  • Microsoft Specialist Windows Devices

Network, virtualisation & infrastructure

  • Cisco CCNA Routing & Switching
  • Citrix CCEE
  • Citrix CCAA
  • Citrix XenDesktop
  • Citrix XenServer
  • Citrix XenApp
  • Sophos SafeGuard Encryption Architect
  • Astaro Certified Engineer
  • Astaro Certified Administrator
  • HP ASP SMB Solutions
  • HP ASP Partner Fundamentals
  • CompTIA Server+ ce
  • CompTIA Server+
  • CompTIA Linux+
  • CompTIA A+ (IT Technician)
  • CompTIA A+ (Remote Support)
  • CompTIA A+ (Depot Technician)

Methods & web

  • Agile Foundation Team Leader
  • CIW Web Associate

Stanford Advanced Cybersecurity Program

  • XACS101 Foundations of Information Security
  • XACS130 Using Cryptography Correctly
  • XACS131 Writing Secure Code
  • XACS133 Web Security
  • XACS255 Network Security

Contact

Press and expert comment

Press enquiries: call or write directly — no contact form.

Talks, panels and board work

Write briefly about the occasion, date and audience, and Martin will get back to you.

Companies and IT leaders

Want your security verified by an independent third party? The first step is a free pre-analysis with Sekuritet.