Skip to main content

Independent since 2005

Security done by experts.
Accelerated with AI.

Security built for a world where attackers use AI. DEFION combines offensive security expertise with AI that continuously detects, validates, and challenges your defenses. You see what’s happening in minutes and act before attackers get in.

Active Defense means your controls are tested continuously, threats are hunted proactively, and response starts within minutes. AI makes it efficient. Experts make it effective.

Real analysts online in Zoetermeer and Barcelona. Average response under 5 minutes.
2.4M events analyzed847 anomalies identified12 threats blockedDetection time: <4 min

DEFION in numbers

20+
Years of experience
100+
Security experts
1,000+
Organizations protected
100,000+
Endpoints monitored
DEFION security experts
Why DEFION

Independent.
AI-accelerated.
20 years proven.

You get advice without a hidden sales agenda. DEFION doesn't sell products, only protection. That means our recommendations are always in your interest.

From boardroom to server room, 24/7 monitoring and AI-accelerated pentesting. One partner for your entire attack surface: IT, OT, and IoT.

About DEFION →
Meet the team

100+ specialists.
Two offices.
One team.

Zoetermeer and Barcelona. Real people, senior expertise. No offshore support, no call-center triage. When you call DEFION, you reach the engineer who can actually help.

Independent since 2005. Still driven by the people who founded it.

The DEFION team together in the mountains during our annual offsite
DEFION engineers collaborating over shared desks
Four DEFION colleagues hanging out in a mountain cabin
Three DEFION colleagues relaxing on a couch after hours
What this means for you

Faster detection.
Less noise.
Better decisions.

You only get alerts that matter. No flood of false positives, no overwhelmed security team. Our technology filters the noise, our experts make the calls.

The result: threats detected in minutes instead of days. And when it counts, there are always people ready who know what to do.

Alert within 4 minutes

No hours or days waiting for an alarm

Only what matters

Your team sees relevant alerts, not thousands

Pentest in 24 hours

First vulnerabilities same day, not after weeks

Experts who decide

No automated guesswork, real human judgment

THREAT INTELLIGENCE

What we see right now.

Week 21, 2026 · Updated May 20, 2026

Our TI team monitors 40+ sources 24/7. These are the most relevant threats for European organizations.

CVE · CRITICAL · All Sectors (NGINX web infrastructure)

CVE-2026-42945: NGINX 18-year-old heap buffer overflow actively exploited in the wild, public PoC available, RCE possible

NGINX CVE-2026-42945: heap buffer overflow actively exploited in the wild. Public PoC on GitHub. RCE possible when ASLR is disabled. NCSC-NL advisory issued. Cisco SD-WAN (CVSS 10.0) also under active attack. Action: patch NGINX to 1.31.0 or 1.30.1 immediately.

May 20, 2026 · Confidence: High

Read more →
Supply Chain · CRITICAL · Technology, SaaS, DevOps, AI (npm/PyPI users)

TeamPCP/UNC6780 Mini Shai-Hulud: coordinated supply chain attack injects malicious code into 84 npm and PyPI artifacts via GitHub Actions

TeamPCP compromised 84 npm/PyPI artifacts via GitHub Actions Pwn Request and OIDC token theft. TanStack, UiPath, Mistral AI, OpenSearch affected. Any org using these packages in CI/CD may be compromised. Action: audit pipelines and rotate OIDC tokens immediately.

May 20, 2026 · Confidence: High

Read more →
Ransomware · HIGH · Energy, Government, Healthcare, Financial Services (Global)

The Gentlemen RaaS: 320+ victims in 50+ countries, 315 percent growth, energy and government focus, internal breach on May 11

The Gentlemen RaaS: 320+ victims across 50+ countries, 315 percent growth. Energy, government, healthcare targeted. Systematic backup destruction before encryption. Dutch victims confirmed (Amstel Securities). Internal breach May 11 may shift operations. Action: deploy detection signatures.

May 20, 2026 · Confidence: High

Read more →
Trusted by leading organizations

What our customers say

All customer stories →

Ready to make your
security AI-proof?

Talk to one of our experts. No obligations, no sales pitch: an honest conversation about your situation.