Martin Stoltenberg Potestas
Martin helps boards, executive teams and IT leaders understand, prioritise and document cyber risk — from the engine room to the boardroom.
He combines more than 25 years in IT with leadership, running companies and board work. The approach is simple: documentation over assumptions. Security that works in practice.

At a glance
- Role
- CEO and founder, Sekuritet — independent IT security advisory in Denmark
- Experience
- More than 25 years in IT and 15 years with cybersecurity as the primary focus — as CISO, CTO, senior architect and company founder
- Public appointment
- Appointed external examiner in IT security and IT development, 2025–2029: designated to assess exams at Danish higher-education IT programmes
- Leadership & board
- Experience as CEO, CTO, company founder and chairman of the board · today chairman of the residents’ board at Nørrevang and member of the board of the housing association Herlev Boligselskab · member of the Danish Board Association (Bestyrelsesforeningen) · CBS Executive board director programme · Harvard Business School, Certificate of Specialization in Leadership and Management · AP degree in leadership and management
- Security & governance
- CISSP, CCSP, CISM, CISA, CRISC · ISO/IEC 27001 Senior Lead Implementer and Senior Lead Auditor, i.e. certified both to build and to audit security · NIS2 Directive Senior Lead Implementer · ISO/IEC 27005 Senior Lead Risk Manager
- Offensive security & incident response
- GPEN, GCIH and GSEC · GIAC Advisory Board (by invitation after a top score on a GIAC exam) · Certified Ethical Hacker · Lead Pen Test Professional · ISO/IEC 27035 Senior Lead Incident Manager
- Cloud & Microsoft
- CCSP and Senior Lead Cloud Security Manager · Microsoft 365 Enterprise Administrator Expert, Azure Administrator and Windows Server Hybrid · 26 Microsoft certifications in total
- Focus areas
- Cyber risk and governance · advising boards and executive teams · CISO Service · penetration testing, Assume Breach and offensive security · security assessments of Microsoft 365 and Active Directory · identity and access management · cloud and hybrid environments · supplier and third-party risk · NIS 2, ISO 27001 and risk management · security awareness · AI governance · preparedness and incident response
- Languages
- Danish (native), English (professional)
Good cybersecurity is not about implementing as much as possible. It is about understanding the risk, prioritising correctly and being able to document that the chosen security measures work.
How Martin works
Martin is direct in his assessments but respectful of the people who carry the responsibility. He makes complex problems understandable, says clearly when something cannot yet be concluded, and does not recommend more security than the risk requires.
Documentation before conclusions
Analyses that can be checked, and reports management can act on.
Plain language without unnecessary drama
What is documented, what is likely and what we do not yet know are kept clearly apart.
Recommendations that work in real operations
Prioritised by risk, impact and practical feasibility — not theoretical perfection.
Where Martin can contribute
Four routes in, depending on whether you are looking for advice for your organisation, are a journalist or an organiser, or carry the responsibility in an executive team or board.
For companies and IT leaders
Independent advice and concrete engagements through Sekuritet. The first step is always a free pre-analysis with a fixed price:
- Microsoft 365 security assessment
- Active Directory security assessment
- Penetration testing
- Assume Breach
- CISO Service — a permanent, independent security partner
- NIS 2 — gap analysis and documentation (in Danish)
- Security awareness and phishing simulation
Sekuritet verifies your security. We do not run your IT.
For the media
Need an expert assessment? Martin comments on, among other things:
- current cyberattacks and data breaches
- ransomware and digital extortion
- NIS 2 and management responsibility
- attacks on Microsoft 365, identity environments and Active Directory
- preparedness, backup and recovery
- boards’ responsibility for cyber risk
- education and the cybersecurity skills gap
Martin distinguishes clearly between what is documented, what is likely and what we do not yet know.
Press enquiries: call directly on +45 30 96 31 31 or write to martin@sekuritet.com.
Latest appearance: The Sidechannel on insecure mail servers in Denmark (21 September 2026)
Talks and panel debates
Book Martin for a keynote, panel debate or expert briefing. Possible topics:
- Cybersecurity from the engine room to the boardroom
- Documented security instead of assumptions
- What should the board actually ask?
- When the cyber response plan meets reality
- NIS 2 without compliance theatre
Advisory and board work
Strategic sparring on cyber risk and digital resilience. Martin has six years of experience as chairman of the board and today serves on boards in the Danish non-profit housing sector. His particular contribution in the boardroom is making complex technology and cyber risks concrete enough for the board to prioritise, oversee and decide. He contributes especially within:
- cyber and technology risk
- digital resilience and preparedness
- management reporting and controls
- critical supplier dependencies
- technology and security strategy
- AI governance and information protection
Press biography for free use
Both texts may be used freely. A portrait is available on request.
Short (for a byline or fact box)
Martin Stoltenberg Potestas is a cybersecurity expert, CEO and founder of Sekuritet, and a former CISO and CTO. He has more than 25 years in IT and began specialising in cybersecurity in 2011. He holds the CISSP, CISM, CISA and GPEN certifications, among others, and is an appointed external examiner in IT security and IT development for 2025–2029.
Long (for a profile or programme)
Martin Stoltenberg Potestas is a cybersecurity expert, CEO and founder of Sekuritet, an independent IT security advisory in Denmark. He has more than 25 years in IT infrastructure as infrastructure architect, CTO and CISO, began specialising in cybersecurity in 2011 and has founded several companies. He advises boards, executive teams and IT leaders on cyber risk, from the engine room to the boardroom, and holds the CISSP, CCSP, CISM, CISA, CRISC, GPEN and GCIH certifications among others. He has completed Stanford’s Advanced Cybersecurity Program, Harvard Business School’s Certificate of Specialization in Leadership and Management and CBS Executive’s board director programme, and is an appointed external examiner in IT security and IT development for 2025–2029.
In the media
Martin contributes as an expert source on current cyber threats, security incidents and the management consequences of technical risk.
Insecure email servers exposed are 'open invitation to cybercriminals'
Ingeniøren’s English-language sister publication carries the article on the mapping in English: 359 Danish Exchange findings, 242 of them out of support, and Martin’s assessment of Exchange as one of the most trusted components of the entire IT infrastructure.
Read the article at The Sidechannel →Subscription required
Kommuner hastelukker internetadgang til gamle e-mailsystemer
Follow-up article based on the same mapping: five municipalities had outdated Exchange servers exposed to the internet while the Danish Agency for Social Security conducts NIS 2 supervision of municipalities. Several municipalities closed access after Ingeniøren contacted them.
Read the article at Ingeniøren (in Danish) →Subscription required
359 forældede danske mailservere står stadig åbne mod internettet
Computerworld relays Ingeniøren’s coverage of the Sekuritet mapping: 359 Danish Exchange findings, 242 of them out of support, and Martin’s assessment of why an Exchange server is one of the most trusted components in the entire IT infrastructure.
Read the article at Computerworld (in Danish) →Subscription required
Hundreder af usikre mailservere blotlagt i Danmark: »En stående invitation til cyberkriminelle«
The article is based on a mapping carried out by Martin at Sekuritet and examines the risk posed by hundreds of internet-exposed mail servers at Danish public authorities and companies. Ingeniøren presented the findings to the organisations concerned, and Martin contributes the expert assessment.
Read the article at Ingeniøren (in Danish) →Subscription required
240 Usikre Mailservere Afsløret I Danmark [2026]
The news site Shattered relays Ingeniøren’s coverage and credits Martin and Sekuritet with the technical research behind the findings on outdated mail servers.
Own analyses and articles
Martin’s own analyses and professional perspectives, written for decision-makers in Danish: technical understanding, a management perspective and a clear thesis.
- Exchange på lånt tid: 242 danske servere — og fristen 1. november17 September 2026
- NIS 2: Hvordan ved I, om I er i mål?10 September 2026
- Penetrationstest, Assume Breach, scanning eller sikkerhedsanalyse?1 September 2026
- Informationssikkerhed på hospitalet: hvad jeg så fra venteværelset12 August 2026
Clients on working with Sekuritet
Sekuritet has advised, among others, Unilite, Cadpeople, Kunde & Co and Bitcoin Suisse.
»The assessment we received deserves a 10 out of 10 without hesitation.«
»Sekuritet challenged that decision and recommended starting with a security assessment instead. It turned out to be the right call.«
Experience
Current
- 2022–CEO and founder, SekuritetPrimary role.
- 2025–Appointed external examiner in IT security and IT development (2025–2029)
- 2026–Co-founder and CEO, Governance Privacy IntelligenceSecure and controlled use of AI in organisations: AI governance and controlled access to language models.
- 2020–Founder, Amplus ApS
- Chairman, residents’ board at Nørrevang, Herlev Boligselskab
- Board member, Herlev Boligselskab
- Member, Danish Board Association (Bestyrelsesforeningen)
Previous
- Chairman and vice-chairman, Round Table 60 Herlev
- 2018–2022Co-founder and managing partner, Sipato
- 2016–2022Chairman of the board, Sipato
- 2015–2018CISO, Progressive A/S
- 2015CTO, Systemhosting A/S
- 2011–2015Senior architect and technical lead, Progressive A/S
- 2007–2011Infrastructure architect, Cortex Consult A/S
- 2003–2007Founder, IceSystems
- 2000–2003IT consultant, Colberghus
Education
- 2025Stanford School of Engineering / Stanford Online – Advanced Cybersecurity ProgramStanford’s technical deep-dive in cybersecurity: how cryptography fails in practice, how secure code is written, and how web and network attacks work and are defended against. It is the technical foundation beneath the advice: Martin can verify what a vendor claims instead of taking it on trust. Five courses: Foundations of Information Security, Using Cryptography Correctly, Writing Secure Code, Web Security and Network Security.
- 2023–2024CBS Executive – Board director programme (Bestyrelsesuddannelsen)Denmark’s most established board director programme, developed by CBS with EY and Kromann Reumert. A 360-degree view of board work: the board’s legal responsibilities, accounts and capital, strategy and value creation, the interplay between board and management, and digitalisation and cybersecurity as a board topic. The exam is run as a board meeting. For Martin it is the bridge between technology and the boardroom: he knows the frameworks cyber risk must be translated into before a board can act on it.
- 2021–2022Harvard Business School – Certificate of Specialization in Leadership and ManagementHarvard Business School’s leadership courses taught by the case method: real dilemmas from real companies, where participants must make and defend decisions as leaders do. The specialization covers leading people, organisations and change. For Martin it is the leadership side of being a CISO and CEO: making security happen in an organisation, not just on paper.
- 2021CBS Executive – Economic Management and Strategic DevelopmentExecutive programme in financial management and strategic development.
- 2011–2017Copenhagen Business Academy – AP Degree in Leadership and ManagementHigher education in leadership completed part-time alongside work: leadership in practice, organisation and strategic leadership.
- 2009–2010IT University of Copenhagen – IT Project ManagementIT project management at university level.
- Business Academy Aarhus – Diploma in IT securityDiploma programme in IT security at bachelor level.
Certifications
Martin’s certifications span cyber governance and audit, penetration testing, incident response, cloud, Microsoft and classic infrastructure. The most important:
- CISSP
- CCSP
- CISM
- CISA
- CRISC
- GPEN
- GCIH
- ISO/IEC 27001 Senior Lead Implementer and Senior Lead Auditor
- NIS2 Directive Senior Lead Implementer
- Microsoft 365 Enterprise Administrator Expert
80+ certifications and completed specialist courses
See 70 selected certifications and specialist courses
Security, audit & governance
- CISSP (ISC2)
- CCSP (ISC2)
- SSCP (ISC2)
- CISM (ISACA)
- CISA (ISACA)
- CRISC (ISACA)
- NIS2 Directive Senior Lead Implementer (PECB)
- ISO/IEC 27001 Senior Lead Implementer (PECB)
- ISO/IEC 27001 Senior Lead Auditor (PECB)
- ISO/IEC 27005 Senior Lead Risk Manager (PECB)
- ISO/IEC 27035 Senior Lead Incident Manager (PECB)
- Senior Lead Cybersecurity Manager (PECB)
- Senior Lead Cloud Security Manager (PECB)
Offensive security & incident response
- GIAC Penetration Tester (GPEN)
- GIAC Certified Incident Handler (GCIH)
- GIAC Security Essentials (GSEC)
- GIAC Advisory Board
- Lead Pen Test Professional (PECB)
- Certified Ethical Hacker (CEH)
- CIW Web Security Professional
Microsoft 365, Azure & Windows Server
- Microsoft 365 Enterprise Administrator Expert
- Microsoft 365 Modern Desktop Administrator
- Microsoft 365 Messaging Administrator
- Azure Administrator (AZ-104)
- Windows Server Hybrid (AZ-801)
- MS-100 Identity
- MS-101 Security
- MCSE Productivity
- MCSE Messaging
- MCSE Cloud Platform
- MCSA Windows Server 2016
- MCSA Windows Server 2012
- MCSA Windows Server 2008
- MCSA Windows 10
- MCITP Enterprise Administrator
- MCITP Server Administrator
- MCITP Enterprise Messaging
- MCTS Active Directory 2008
- MCTS Network 2008
- MCTS Applications 2008
- MCTS Exchange 2010
- Microsoft Specialist Exchange 2016
- Microsoft Specialist Office 365
- Microsoft Specialist Hyper-V
- Microsoft Specialist Windows 7
- Microsoft Specialist Windows Devices
Network, virtualisation & infrastructure
- Cisco CCNA Routing & Switching
- Citrix CCEE
- Citrix CCAA
- Citrix XenDesktop
- Citrix XenServer
- Citrix XenApp
- Sophos SafeGuard Encryption Architect
- Astaro Certified Engineer
- Astaro Certified Administrator
- HP ASP SMB Solutions
- HP ASP Partner Fundamentals
- CompTIA Server+ ce
- CompTIA Server+
- CompTIA Linux+
- CompTIA A+ (IT Technician)
- CompTIA A+ (Remote Support)
- CompTIA A+ (Depot Technician)
Methods & web
- Agile Foundation Team Leader
- CIW Web Associate
Stanford Advanced Cybersecurity Program
- XACS101 Foundations of Information Security
- XACS130 Using Cryptography Correctly
- XACS131 Writing Secure Code
- XACS133 Web Security
- XACS255 Network Security
Contact
Press and expert comment
Press enquiries: call or write directly — no contact form.
Talks, panels and board work
Write briefly about the occasion, date and audience, and Martin will get back to you.
Companies and IT leaders
Want your security verified by an independent third party? The first step is a free pre-analysis with Sekuritet.