Transparency Act

Updated 24.06.2026

1. Introduction

Netsecurity AS is a Norwegian cybersecurity company owned by the Å Energi Group and its employees. This statement constitutes the company’s public reporting under the Transparency Act for 2025.

The Transparency Act shall promote enterprises’ respect for fundamental human rights and decent working conditions, and ensure the public access to information on how enterprises handle actual and potential adverse impacts. Netsecurity is subject to the Act and complies with both the duty to publish a statement and the duty to carry out due diligence assessments.

The content of the statement follows guidance from the Norwegian Consumer Authority, the OECD Guidelines for Multinational Enterprises and the UN Guiding Principles on Business and Human Rights, as well as the Group’s and the company’s internal procedures for risk and due diligence assessments. The statement is structured in accordance with the requirements of section 5 of the Transparency Act and forms part of the Å Energi Group’s overall work on human rights and decent working conditions.

Å Energi Statement under the Transparency Act

https://www.aenergi.no/no/rett-til-informasjon-ifolge-apenhetsloven 

2. Business and organization

Netsecurity AS delivers expertise, solutions and services within IT and OT - Industrial Cybersecurity, and is one of Norway’s largest providers in this area. We help public and private enterprises prevent, detect and manage cyberattacks through advisory services, security monitoring and Incident Response – around the clock, all year round.

The company has around 700 customers in both the private and public sectors across the Nordic region. The business is primarily expertise- and service-based. Key figures for 2025 compared with 2024 are shown in the table below.

 

  2025 2024
Number of employees 171 approx. 160
Revenue approx. 854 million. approx. 800 million.
Suppliers and business partners 452 approx. 400
Customers approx. 700 approx. 700

 

The supplier portfolio consists predominantly of national and international players for the purchase of hardware, licenses and services. A limited share of goods purchases is linked to hardware from a small number of manufacturers and distributors.

3. Guidelines and routines

Netsecurity follows the Å Energi Group’s guidelines and policies for safeguarding human rights and decent working conditions, and has prepared its own guidelines based on these. The key governing documents are:

  • Code of Conduct for employees, which applies to all employees, hired personnel and persons acting on behalf of the company.

  • Code of Conduct for suppliers and business partners, which applies to all companies and individuals that supply goods or services to Netsecurity, including their employees, subcontractors and representatives. The guidelines require suppliers to support and respect internationally recognized human rights, carry out their own due diligence assessments in line with the UN Guiding Principles, and comply with the ILO core conventions on freedom of association, collective bargaining and the prohibition of forced labour, child labour and discrimination.

    Breaches of the company’s Code of Conduct for suppliers may result in termination of contract, claims for compensation, disqualification as a supplier and/or reporting to the relevant authorities.

Netsecurity selects only certified parties that themselves report publicly on their corporate social responsibility. The company is currently certified under ISO 9001 (quality management), ISO 14001 (environmental management) and ISO 27001 (information security). Among other things, these standards set requirements for social conditions, including the working environment, employee health and safety, as well as for continuous improvement and systematic management.

The company has internal and external whistleblowing channels that enable employees, hired personnel and external third parties to safely and easily report misconduct. The arrangement ensures protection against retaliation. Group Internal Audit has the overall responsibility for following up whistleblowing cases.

Responsibility for work on quality, environment and sustainability is anchored in the company’s management. A dedicated role as Quality and Sustainability Manager has been established, and work on human rights and decent working conditions forms an integrated part of the company’s sustainability strategy. The company’s management system for information security, quality and environment/sustainability provides the framework for systematic management and continuous improvement in these areas.

To safeguard decent working conditions in its own operations, Netsecurity works systematically with the working environment, equal treatment and employee development. Key measures include working environment surveys with follow-up actions, leadership development, as well as work on salary policy and equal pay to ensure fair and non-discriminatory treatment. The company cooperates with occupational health services on the working environment, health and the working environment committee, and emphasizes diversity and inclusion.

4. Due diligence assessments and risk

Netsecurity carries out due diligence assessments as an integrated part of the Å Energi Group’s overall work, supplemented by assessments specific to the company’s own operations and supply chain.

As an expertise- and service-based cybersecurity company, the risk of breaches of human rights and decent working conditions in its own operations is considered low. Employees work mainly in Norway and Sweden under national regulations, and the working environment is safeguarded, among other things, through the ISO 14001 system.

The risk is mainly linked to the supply chain and is concentrated in two areas:

  • Services and licenses from national and international suppliers. The risk is considered low to moderate, as the portfolio largely consists of established players that themselves report on corporate social responsibility.

  • Hardware originating from manufacturers that may use subcontractors in Asia, including China. In these parts of the value chain, there is an inherent and elevated risk of adverse impacts on human rights and decent working conditions, particularly related to forced labour, forced overtime, lack of freedom of association and weak traceability in the early tiers. Limited visibility into lower supplier tiers makes such risk challenging to fully verify.

The risk is managed through a risk-based approach to supplier follow-up, where efforts are prioritized toward the areas with the greatest opportunity for influence. Specifically, this includes, among other things:

  • selecting certified suppliers that themselves report publicly on corporate social responsibility,

  • obtaining documentation of the supplier’s policy and compliance,

  • assessing risk when entering into contracts, including through the use of risk registers, geographic risk assessments and publicly available information,

In 2025, no actual incidents, non-conformities or whistleblowing cases have been identified that indicate material breaches of human rights or decent working conditions in its own operations or among prioritized suppliers.

5. Measures implemented in 2025

During 2025, Netsecurity has:

  • Completed the conversion of environmental certification from Eco-Lighthouse to ISO 14001, with related requirements for social conditions, the working environment and safety.

  • Revised the Code of Conduct for suppliers and business partners.

  • Continued the mapping and risk assessment of the supplier portfolio.

  • Contributed to the Group’s work on coordinating Transparency Act and sustainability reporting.

6. The way forward in 2026

For 2026, Netsecurity plans to:

  • Develop a clear sustainability strategy

  • Continue and strengthen risk-based follow-up of suppliers

  • Follow up prioritized suppliers with relevant audits and reporting requirements.

  • Further develop employee training in the Code of Conduct, whistleblowing and due diligence assessments.

  • Complete the remaining measures from the Group’s action plan, including guidelines for remedy and measures in the event of identified breaches.

  • Operationalize the management system for information security, quality and environment/sustainability throughout the organization, and fill the role of Quality and Sustainability Manager.

7. Access to information and communication

Everyone has the right to information on how Netsecurity handles actual and potential adverse impacts on human rights and decent working conditions, cf. section 6 of the Transparency Act. Inquiries may be addressed to the company via the website netsecurity.no and will normally be answered within three weeks.

The due diligence assessments are presented to Netsecurity’s management team, together with guidance from the owner and risk-reducing measures. The obligation to publish a statement in accordance with the requirements of the Transparency Act forms part of the Board of Directors’ annual report. The statement is published on the company’s website.

 

Download the document