DEFION in numbers
Five disciplines.
One partner.
No juggling five vendors for five problems. One team that covers your entire security posture, from advisory to 24/7 monitoring and crisis response.
Independent.
AI-accelerated.
20 years proven.
You get advice without a hidden sales agenda. DEFION doesn't sell products, only protection. That means our recommendations are always in your interest.
From boardroom to server room, 24/7 monitoring and AI-accelerated pentesting. One partner for your entire attack surface: IT, OT, and IoT.
About DEFION →
100+ specialists.
Two offices.
One team.
Zoetermeer and Barcelona. Real people, senior expertise. No offshore support, no call-center triage. When you call DEFION, you reach the engineer who can actually help.
Independent since 2005. Still driven by the people who founded it.




Faster detection.
Less noise.
Better decisions.
You only get alerts that matter. No flood of false positives, no overwhelmed security team. Our technology filters the noise, our experts make the calls.
The result: threats detected in minutes instead of days. And when it counts, there are always people ready who know what to do.
Alert within 4 minutes
No hours or days waiting for an alarm
Only what matters
Your team sees relevant alerts, not thousands
Pentest in 24 hours
First vulnerabilities same day, not after weeks
Experts who decide
No automated guesswork, real human judgment
What we see right now.
Week 21, 2026 · Updated May 20, 2026
Our TI team monitors 40+ sources 24/7. These are the most relevant threats for European organizations.
CVE-2026-42945: NGINX 18-year-old heap buffer overflow actively exploited in the wild, public PoC available, RCE possible
NGINX CVE-2026-42945: heap buffer overflow actively exploited in the wild. Public PoC on GitHub. RCE possible when ASLR is disabled. NCSC-NL advisory issued. Cisco SD-WAN (CVSS 10.0) also under active attack. Action: patch NGINX to 1.31.0 or 1.30.1 immediately.
May 20, 2026 · Confidence: High
Read more →TeamPCP/UNC6780 Mini Shai-Hulud: coordinated supply chain attack injects malicious code into 84 npm and PyPI artifacts via GitHub Actions
TeamPCP compromised 84 npm/PyPI artifacts via GitHub Actions Pwn Request and OIDC token theft. TanStack, UiPath, Mistral AI, OpenSearch affected. Any org using these packages in CI/CD may be compromised. Action: audit pipelines and rotate OIDC tokens immediately.
May 20, 2026 · Confidence: High
Read more →The Gentlemen RaaS: 320+ victims in 50+ countries, 315 percent growth, energy and government focus, internal breach on May 11
The Gentlemen RaaS: 320+ victims across 50+ countries, 315 percent growth. Energy, government, healthcare targeted. Systematic backup destruction before encryption. Dutch victims confirmed (Amstel Securities). Internal breach May 11 may shift operations. Action: deploy detection signatures.
May 20, 2026 · Confidence: High
Read more →We speak your language.
Newsroom
AZ and DEFION Security: Official Supplier for Optimal Data Protection
AZ and DEFION enter into a multi-year strategic partnership as Official Supplier to strengthen the club's digital resilience. DEFION protects the valuable data AZ uses for performance on and off the pitch.
CVE-2026-31431 ("Copy Fail"): Critical Linux Privilege Escalation Vulnerability Explained
CVE-2026-31431 ("Copy Fail") is a Linux kernel vulnerability enabling stealthy privilege escalation to root. Learn about the impact, affected systems, and mitigation steps.
SURF Deployment: DEFION and DTX Secure 75+ Education and Research Institutions
DTX and DEFION begin rolling out MDR services for SURF. More than 75 Dutch universities, polytechnics and vocational colleges receive 24/7 protection against cyberattacks.
Ready to make your
security AI-proof?
Talk to one of our experts. No obligations, no sales pitch: an honest conversation about your situation.
® 










