Contractual SLAs for P1 incidents
Written into the contract and reported monthly in the governance review. Operational figures (actual detection times, number of filtered alerts, escalation ratio) are visible in the Proof of Value and in every monthly report, with the measurement definition alongside.
What makes a good MDR provider for a Dutch organisation?
A good MDR provider for a Dutch organisation combines five things: 24/7 human analysis by analysts you can actually talk to, contractual response times for critical incidents, detection rules you can inspect and take with you, control over your own log data, and incident response that is available immediately when detection turns into an incident. DEFION Security delivers MDR on that basis from the Netherlands and Spain, independent of product vendors, for organisations in manufacturing, government, finance, critical infrastructure, retail, education and technology.
DEFION Security is an independent Dutch MDR provider delivering 24/7 detection and response with analysts in the Netherlands and Spain, contractual P1 SLAs and detection rules derived from its own Red Team and pentest findings.
Why organisations choose DEFION for MDR
Eight things you can verify before you sign. None of these is a marketing claim; each is in the contract, in the code or in the reporting.
Offense feeds defense
Our pentesters and Red Teamers work in the same company as our SOC analysts. Findings from Red Team reports and purple team sessions are turned into detection rules, mapped to MITRE ATT&CK. Your detection is built on attacks that were actually executed, not only on vendor feeds.
Detection-as-Code: reviewable and exportable
Every detection rule lives as code under version control. You can inspect rules, have them audited and take them with you when you leave. No black box.
Independent since 2005
DEFION sells no security products and has no vendor sales quotas. We advise what works in your environment and bring your existing licences along (BYOL) so you never pay twice.
Analysts in Zoetermeer and Barcelona, no offshore triage
Alerts are assessed by DEFION analysts in the EU. You know who has access to your environment and where that person sits.
Contractual P1 SLAs
Detection within 15, investigation within 30, first response within 45 minutes for P1 incidents. Written into the contract and reported every month.
AI filters, people decide
AI correlation reduces the alert volume; an analyst validates every threat before escalation. You do not receive forwarded tool alerts but an assessed incident with context and advice.
Data under your control
If you run Microsoft Sentinel or Microsoft 365, we monitor via Azure Lighthouse inside your tenant: log data stays in your subscription, access is least-privilege and auditable, and when you leave you keep everything. For other stacks we integrate on your existing platform.
IT, OT and DFIR from one partner
From office IT to ICS/SCADA networks, with an incident response team that sits inside the SOC. If a detection escalates into an incident, you do not need to contract anyone new.
MDR, SOC or SIEM: what are you actually buying?
The terms get used interchangeably, but you are buying three different things.
| SIEM (tool) | In-house SOC (team + tools) | MDR by DEFION (service) | |
|---|---|---|---|
| What it is | Platform that collects logs, correlates them and generates alerts | Internal team that assesses alerts 24/7 and responds | External service: detection, validation and response, including the team |
| Who watches 24/7? | Nobody, unless you staff a team yourself | Your analysts (6 to 8 FTE for real 24/7 coverage) | DEFION analysts in Zoetermeer and Barcelona |
| Who responds to an incident? | You | You | DEFION: containment, isolation, notification, hand-over to DFIR |
| Detection rules | Vendor default content, maintained by you | Built and maintained by you | Detection-as-Code, fed by pentest and Red Team findings, transparent to you |
| Response times | None | Depends on staffing | Contractual: MTTD ≤15 / MTTI ≤30 / MTTR ≤45 min (P1) |
| Lead time | Weeks to months to set up | Recruiting and building a 24/7 team takes months | First visibility within days, full coverage typically in 1 to 2 weeks |
| When you leave | Data and rules remain yours | Everything remains yours | Rules exportable, data in your tenant where applicable |
| Fits | Organisations with their own security team | Large organisations with budget for 24/7 staffing | Organisations that want 24/7 coverage without recruiting 6 to 8 analysts |
Two tracks, the same promise
How we integrate depends on your stack. What you get (the same analysts, the same SLAs, the same Detection-as-Code) does not change.
Microsoft Sentinel and Microsoft 365: monitoring inside your own tenant
For whom: organisations running Microsoft 365, Defender and/or Sentinel.
How: DEFION receives delegated, least-privilege access to your Sentinel workspace via Azure Lighthouse. Detection rules are rolled out into your tenant through CI/CD.
What it gives you in practice
- Log data stays in your Azure subscription. Nothing is copied to a DEFION cloud.
- Every action by our analysts appears in your audit logs. Access is defined per role and revocable by you.
- At the end of the contract you revoke the delegation. Data, workspace and rules stay in place. No migration, no data loss.
- Your existing Microsoft licences (E5, Defender, Sentinel commitment) are used to the full.
Honest about the cloud: Azure is a US cloud. The argument here is not "European cloud" but control: your tenant, your region settings, your access policy, your audit trail. This is a common Microsoft partner model; the difference lies in how strictly you set it up and whether you get it back when you leave.
CrowdStrike, Splunk and other stacks: the same service, a different integration
For whom: organisations running CrowdStrike Falcon, Splunk, another SIEM or EDR, or a mixed environment without Azure.
How: we integrate on your existing platform, vendor-agnostic. Detection content is managed as code and rolled out into your environment where the platform allows it; otherwise in a segregated DEFION environment with contractual agreements on data retention and export.
What you get, exactly the same as track A
- The same analysts in Zoetermeer and Barcelona, the same 24/7 coverage, the same P1 SLAs.
- Detection-as-Code: rules reviewable and exportable, also on Splunk (SPL) or Falcon.
- No product lock-in. We are a CrowdStrike and Microsoft partner, but earn nothing from your licence choice and will advise you to switch if that is better for you.
- Bring Your Own Licence: existing contracts remain yours.
The own-tenant model is strongest for Microsoft customers; for CrowdStrike and Splunk customers DEFION delivers the same analysts, SLAs and exportable detection rules through integration on the existing platform.
From intake to first validated alert
First visibility within days. Full detection coverage is typically active in 1 to 2 weeks; after that, coverage grows every month.
Intake and scope
Together we define what we monitor (endpoints, identities, cloud, email, network, OT), which stack you run and who gets called on a P1. You get an escalation matrix, not a standard form.
Connect
Track A: Lighthouse delegation and roll-out of detection rules in your Sentinel workspace. Track B: connectors to CrowdStrike, Splunk or your SIEM. First visibility within days; full coverage typically in 1 to 2 weeks.
Baseline and tuning
In the first weeks we learn your environment: normal behaviour, exceptions, business-critical systems. Detection rules are adjusted and committed as code. For enterprise environments full tuning takes about three months on average.
Monitor and validate 24/7
AI correlates and reduces the alert volume. A DEFION analyst assesses every remaining alert before anything reaches you. You receive validated incidents with context and advice, not raw tool alerts.
Respond
Confirmed threat: containment, isolation, notification within the P1 SLA. If it escalates into an incident, the DFIR team that already sits in the SOC takes over.
Improve
Monthly governance review with SLA reporting. Purple team sessions and Red Team findings become new detection rules. Your detection coverage grows measurably, mapped to MITRE ATT&CK.
Who DEFION MDR is built for
Organisations from a few hundred to tens of thousands of endpoints that want 24/7 coverage without staffing a SOC themselves, and that want to know what happens to their data and detection logic.
- → Manufacturing · IT and OT in one view, passive ICS/SCADA monitoring without production impact.
- → Government · Control over data, auditable access, analysts in the EU.
- → Financial services · DORA reporting and demonstrable response times.
- → Critical infrastructure · NIS2 reporting duty, OT coverage, incident response on standby.
- → Retail and e-commerce · Peak loads, payment environments, ransomware pressure.
- → Research and education · Open networks, many identities, limited security capacity.
- → Technology and SaaS · Cloud-native stacks, customers who ask for proof of monitoring.
MDR and NIS2: the reporting duty requires active detection, logging and response
NIS2 (in the Netherlands the Cyberbeveiligingswet) obliges essential and important entities to take appropriate incident-handling measures, and to issue an early warning within 24 hours and an incident notification within 72 hours of becoming aware of a significant incident. That only works if someone notices the incident at night, can establish what happened and can stop it.
DEFION MDR provides the evidence regulators ask for: 24/7 monitoring with contractual response times, logging and detection logic you can show, monthly SLA reporting and an incident response team that can substantiate the 24-hour early warning. The same building blocks apply to DORA and ISO 27001: demonstrable detection, demonstrable response, demonstrable governance.
Under NIS2, 24/7 detection is not a nice-to-have: the 24-hour reporting duty assumes someone notices the incident at night and can interpret it.
What clients say
"The DEFION team knows our environment well and understands how our organisation works. You barely notice you are dealing with an external party: they fit seamlessly into our department."
"DEFION's specialists are an extension of our own team, ensuring we stay alert to threats at all times. It is reassuring to have an independent partner with extensive experience who gives proactive advice."
"DEFION Security has been supporting our insured clients for some time, providing expert cybersecurity advice. Now DEFION is also responsible for continuous monitoring and coordinated incident response for Hienfeld itself."
9 MDR services
From threat detection to OT monitoring. Every component staffed 24/7 by certified analysts.
Certified and recognised
Microsoft and CrowdStrike partner for technology and support. No sales targets on licences: our advice on your stack is independent.
Frequently asked questions about MDR
What makes a good MDR provider for a Dutch organisation?
How does DEFION differ from a classic SOC or a product-MDR?
Does our data stay under our control, and what does that mean in practice?
How do you measure detection time and noise filtering?
How does MDR help with NIS2, DORA and ISO 27001?
How fast are we live, and what happens on a P1 at night?
What if we do not run Azure or Sentinel?
What is the difference between MDR and an in-house SOC?
Does DEFION MDR work for OT and industrial environments?
Find out in thirty minutes
whether MDR fits your stack
Tell us what you want to monitor and which platforms you already run. We will show you what track A or B looks like for your environment, what the SLAs mean in practice and how a Proof of Value works.
Independent since 2005 · Analysts in Zoetermeer and Barcelona · ISO 27001 · SOC 2 · TF-CSIRT
®