About Innnes
Innnes is the largest food wholesaler in Iceland, and a big part of standing out has been building a genuine culture of cybersecurity. For the company, security is both a way to compete and a responsibility to its customers and community, and it's a story it's happy to share.
What Aftra provides
- Attack Surface Management
- Continuous threat and vulnerability monitoring
- Security Score
- Security Campaigns
This story, in short
This is a story about culture and confidence, and about how a company went from a bruising pentest to a security score of 95 out of 100.
You'll hear from the two people who led the way: Tinna Harðardóttir, CTO, and Berglind Grímsdóttir, CISO at Innnes.
What Innnes needed help with
Innnes had grown, but its security hadn't quite kept pace. What it needed was:
- A clear view of its infrastructure from the outside.
- Real oversight of its digital footprint and attack surface.
- A way to keep security moving and measurable.
- Buy-in for security across the whole company.
What we brought to the table
Innnes found Aftra through Syndis, its security partner. From there, we brought:
- Continuous monitoring of threats and vulnerabilities, laid out visually.
- A clear picture of their attack surface.
- A Security Score the whole team could rally around.
- Security Campaigns that show each person their own digital footprint.

The main challenge: a company that had outgrown its old habits
"Not too long ago, Innnes was a typical Icelandic company with a warehouse," says Tinna Harðardóttir, the company's CTO, who has been there for more than twenty years.
When Innnes moved to the Reykjavik harbor in 2021, something shifted in how the whole company thought. Technology was moving fast, Innnes had fallen behind on cybersecurity, and it was clearly time to step up.
Convincing everyone to invest wasn't easy at first, but this is a company that isn't afraid of a difficult conversation, and buy-in from leadership followed soon enough.
The harsh awakening
The real turning point came through Syndis, an Icelandic cybersecurity firm and an Aftra partner.
The "aha" moment arrived after a Syndis pentest, which showed that Innnes had almost no idea how its infrastructure looked from the outside.
They had no oversight of their digital footprint or attack surface, and the results made the management team see just how vast that surface was. They also came to realize that they couldn't possibly manage it all on their own.
Choose people you enjoy working with
Tinna and Berglind lead security at Innnes, and both put real weight on strong partnerships.
Innnes started with Syndis's security operations center, then added its security management services. They've already done the groundwork to be ready for NIS2 and are working toward ISO 27001, and it was that trust in Syndis that led them to add the Aftra Attack Surface Management platform.
The work we're proud of
For Innnes, adding Aftra was the missing piece of the puzzle.
It gives the team continuous monitoring for threats and vulnerabilities, all shown visually, and it keeps fixes moving quickly.
When Aftra flags a vulnerability, their Chief System Administrator can take a look and get it resolved fast. On top of that, it gives them a Security Score the whole team can see and act on, and Security Campaigns that put each employee's digital footprint in front of them.
Getting the CEO involved
One of the biggest shifts was at the top. Aftra helped bring the CEO into security, and he became a champion for it.
Since Innnes brought Aftra in, they've raised their Security Score to 95 out of 100, and the CEO was so proud of the number that he showed it to the whole company in a staff meeting.
The score itself is a simple idea: it reflects how resilient an organization is against an attack, and the higher the number, the harder it is for a hacker to get in.
Tinna and Berglind lean on the dashboard to report to leadership, and they check it many times a week.
Everyone has a role to play
A real culture of security reaches well beyond the leadership team, and Aftra Security Campaigns bring that home for everyone.
When Innnes showed people their own digital footprint, it was a wake-up call for many, and staff now understand why they shouldn't be using work accounts for personal activity online.
Plenty of long-serving employees and senior managers carry a large footprint, built up over years when using a work account for personal things was simply normal.
Aftra’s security campaigns make that visible now.
What we learned along the way
Every partnership teaches both sides, and a few lessons stood out with Innnes.
Buy-in from the top matters more than almost anything. You need a champion in leadership, and Innnes has a CEO who understands exactly why security is worth the investment.
It also helps to play a "no blame" game. When people feel safe, they report the incidents that matter, like clicking a bad link, instead of quietly hoping no one notices.
Prepared beats perfect, too. You'll never be 100% confident or 100% secure, but you can absolutely be 100% prepared.
And finally, it pays to share the story. Innnes sees a social responsibility to be open about security, so that others can learn from what they've done.
Why Innnes sticks with Aftra
For Innnes, Aftra was the missing piece that made everything else click into place. It gives the team continuous visibility, quick fixes, and a score the whole company can rally around, and as Berglind puts it, they're simply more at peace now, because they always know where they stand.
In short: here's how we support Innnes
- A score to aim for: Innnes reached and maintains a Security Score of 95 out of 100.
- Faster fixes: vulnerabilities get flagged and resolved quickly.
- A security culture: Security Campaigns turned each employee's digital footprint into a company-wide wake-up call.
- Leadership on board: the CEO checks the score, shares it, and champions security.