Skip to main content
Managed Detection & Response · Netherlands

MDR for organisations in the Netherlands.
24/7 detection without alert noise.

DEFION delivers Managed Detection & Response from Zoetermeer and Barcelona: 24/7 monitoring of endpoints, network, cloud, email and OT, with contractual SLAs for P1 incidents and a DFIR team that sits inside the SOC, not next to it.

We have been independent since 2005 and sell no products. Our pentesters and Red Teamers deliver the attacks our detection rules have to catch. AI filters the volume, analysts decide. You only get called when it matters.

Contractual SLAs for P1 incidents

≤ 15 min
Mean Time to Detect
From incoming event to validated alert
≤ 30 min
Mean Time to Investigate
From alert to confirmed or dismissed threat
≤ 45 min
Mean Time to Respond
From confirmed P1 threat to first containment action
24/7
Coverage
365 days a year, from Zoetermeer and Barcelona

Written into the contract and reported monthly in the governance review. Operational figures (actual detection times, number of filtered alerts, escalation ratio) are visible in the Proof of Value and in every monthly report, with the measurement definition alongside.

What makes a good MDR provider for a Dutch organisation?

A good MDR provider for a Dutch organisation combines five things: 24/7 human analysis by analysts you can actually talk to, contractual response times for critical incidents, detection rules you can inspect and take with you, control over your own log data, and incident response that is available immediately when detection turns into an incident. DEFION Security delivers MDR on that basis from the Netherlands and Spain, independent of product vendors, for organisations in manufacturing, government, finance, critical infrastructure, retail, education and technology.

DEFION Security is an independent Dutch MDR provider delivering 24/7 detection and response with analysts in the Netherlands and Spain, contractual P1 SLAs and detection rules derived from its own Red Team and pentest findings.
Why DEFION

Why organisations choose DEFION for MDR

Eight things you can verify before you sign. None of these is a marketing claim; each is in the contract, in the code or in the reporting.

01

Offense feeds defense

Our pentesters and Red Teamers work in the same company as our SOC analysts. Findings from Red Team reports and purple team sessions are turned into detection rules, mapped to MITRE ATT&CK. Your detection is built on attacks that were actually executed, not only on vendor feeds.

02

Detection-as-Code: reviewable and exportable

Every detection rule lives as code under version control. You can inspect rules, have them audited and take them with you when you leave. No black box.

03

Independent since 2005

DEFION sells no security products and has no vendor sales quotas. We advise what works in your environment and bring your existing licences along (BYOL) so you never pay twice.

04

Analysts in Zoetermeer and Barcelona, no offshore triage

Alerts are assessed by DEFION analysts in the EU. You know who has access to your environment and where that person sits.

05

Contractual P1 SLAs

Detection within 15, investigation within 30, first response within 45 minutes for P1 incidents. Written into the contract and reported every month.

06

AI filters, people decide

AI correlation reduces the alert volume; an analyst validates every threat before escalation. You do not receive forwarded tool alerts but an assessed incident with context and advice.

07

Data under your control

If you run Microsoft Sentinel or Microsoft 365, we monitor via Azure Lighthouse inside your tenant: log data stays in your subscription, access is least-privilege and auditable, and when you leave you keep everything. For other stacks we integrate on your existing platform.

08

IT, OT and DFIR from one partner

From office IT to ICS/SCADA networks, with an incident response team that sits inside the SOC. If a detection escalates into an incident, you do not need to contract anyone new.

Definitions

MDR, SOC or SIEM: what are you actually buying?

The terms get used interchangeably, but you are buying three different things.

  SIEM (tool) In-house SOC (team + tools) MDR by DEFION (service)
What it is Platform that collects logs, correlates them and generates alerts Internal team that assesses alerts 24/7 and responds External service: detection, validation and response, including the team
Who watches 24/7? Nobody, unless you staff a team yourself Your analysts (6 to 8 FTE for real 24/7 coverage) DEFION analysts in Zoetermeer and Barcelona
Who responds to an incident? You You DEFION: containment, isolation, notification, hand-over to DFIR
Detection rules Vendor default content, maintained by you Built and maintained by you Detection-as-Code, fed by pentest and Red Team findings, transparent to you
Response times None Depends on staffing Contractual: MTTD ≤15 / MTTI ≤30 / MTTR ≤45 min (P1)
Lead time Weeks to months to set up Recruiting and building a 24/7 team takes months First visibility within days, full coverage typically in 1 to 2 weeks
When you leave Data and rules remain yours Everything remains yours Rules exportable, data in your tenant where applicable
Fits Organisations with their own security team Large organisations with budget for 24/7 staffing Organisations that want 24/7 coverage without recruiting 6 to 8 analysts
Architecture

Two tracks, the same promise

How we integrate depends on your stack. What you get (the same analysts, the same SLAs, the same Detection-as-Code) does not change.

Track A

Microsoft Sentinel and Microsoft 365: monitoring inside your own tenant

For whom: organisations running Microsoft 365, Defender and/or Sentinel.

How: DEFION receives delegated, least-privilege access to your Sentinel workspace via Azure Lighthouse. Detection rules are rolled out into your tenant through CI/CD.

What it gives you in practice

  • Log data stays in your Azure subscription. Nothing is copied to a DEFION cloud.
  • Every action by our analysts appears in your audit logs. Access is defined per role and revocable by you.
  • At the end of the contract you revoke the delegation. Data, workspace and rules stay in place. No migration, no data loss.
  • Your existing Microsoft licences (E5, Defender, Sentinel commitment) are used to the full.

Honest about the cloud: Azure is a US cloud. The argument here is not "European cloud" but control: your tenant, your region settings, your access policy, your audit trail. This is a common Microsoft partner model; the difference lies in how strictly you set it up and whether you get it back when you leave.

Track B

CrowdStrike, Splunk and other stacks: the same service, a different integration

For whom: organisations running CrowdStrike Falcon, Splunk, another SIEM or EDR, or a mixed environment without Azure.

How: we integrate on your existing platform, vendor-agnostic. Detection content is managed as code and rolled out into your environment where the platform allows it; otherwise in a segregated DEFION environment with contractual agreements on data retention and export.

What you get, exactly the same as track A

  • The same analysts in Zoetermeer and Barcelona, the same 24/7 coverage, the same P1 SLAs.
  • Detection-as-Code: rules reviewable and exportable, also on Splunk (SPL) or Falcon.
  • No product lock-in. We are a CrowdStrike and Microsoft partner, but earn nothing from your licence choice and will advise you to switch if that is better for you.
  • Bring Your Own Licence: existing contracts remain yours.

The own-tenant model is strongest for Microsoft customers; for CrowdStrike and Splunk customers DEFION delivers the same analysts, SLAs and exportable detection rules through integration on the existing platform.

How it works

From intake to first validated alert

First visibility within days. Full detection coverage is typically active in 1 to 2 weeks; after that, coverage grows every month.

01

Intake and scope

Together we define what we monitor (endpoints, identities, cloud, email, network, OT), which stack you run and who gets called on a P1. You get an escalation matrix, not a standard form.

02

Connect

Track A: Lighthouse delegation and roll-out of detection rules in your Sentinel workspace. Track B: connectors to CrowdStrike, Splunk or your SIEM. First visibility within days; full coverage typically in 1 to 2 weeks.

03

Baseline and tuning

In the first weeks we learn your environment: normal behaviour, exceptions, business-critical systems. Detection rules are adjusted and committed as code. For enterprise environments full tuning takes about three months on average.

04

Monitor and validate 24/7

AI correlates and reduces the alert volume. A DEFION analyst assesses every remaining alert before anything reaches you. You receive validated incidents with context and advice, not raw tool alerts.

05

Respond

Confirmed threat: containment, isolation, notification within the P1 SLA. If it escalates into an incident, the DFIR team that already sits in the SOC takes over.

06

Improve

Monthly governance review with SLA reporting. Purple team sessions and Red Team findings become new detection rules. Your detection coverage grows measurably, mapped to MITRE ATT&CK.

Who it is for

Who DEFION MDR is built for

Organisations from a few hundred to tens of thousands of endpoints that want 24/7 coverage without staffing a SOC themselves, and that want to know what happens to their data and detection logic.

NIS2 · DORA · ISO 27001

MDR and NIS2: the reporting duty requires active detection, logging and response

NIS2 (in the Netherlands the Cyberbeveiligingswet) obliges essential and important entities to take appropriate incident-handling measures, and to issue an early warning within 24 hours and an incident notification within 72 hours of becoming aware of a significant incident. That only works if someone notices the incident at night, can establish what happened and can stop it.

DEFION MDR provides the evidence regulators ask for: 24/7 monitoring with contractual response times, logging and detection logic you can show, monthly SLA reporting and an incident response team that can substantiate the 24-hour early warning. The same building blocks apply to DORA and ISO 27001: demonstrable detection, demonstrable response, demonstrable governance.

Under NIS2, 24/7 detection is not a nice-to-have: the 24-hour reporting duty assumes someone notices the incident at night and can interpret it.
Proof

What clients say

20+
Years of experience
100+
Security experts
1,000+
Clients supported
100,000+
Endpoints monitored 24/7

"The DEFION team knows our environment well and understands how our organisation works. You barely notice you are dealing with an external party: they fit seamlessly into our department."

Municipality of Arnhem · IT Department

"DEFION's specialists are an extension of our own team, ensuring we stay alert to threats at all times. It is reassuring to have an independent partner with extensive experience who gives proactive advice."

Dutch State Lottery · Security Management

"DEFION Security has been supporting our insured clients for some time, providing expert cybersecurity advice. Now DEFION is also responsible for continuous monitoring and coordinated incident response for Hienfeld itself."

Hienfeld · Management
All services

9 MDR services

From threat detection to OT monitoring. Every component staffed 24/7 by certified analysts.

Managed Threat Detection

Managed Threat Detection

You only get alerts that matter. AI filters the volume, DEFION analysts validate every threat before escalation. 24/7, with contractual P1 SLAs.

Learn more →
Managed Threat Hunting

Managed Threat Hunting

You know whether threats are hiding in your network that detection tools miss. We hunt proactively, on hypotheses from threat intelligence and our own Red Team work.

Learn more →
Managed XDR

Managed XDR

Unified visibility across endpoints, network, cloud and email. Fully managed, vendor-agnostic, with SOAR integration where needed.

Learn more →
Security Control Validation

Security Control Validation

You know whether your security measures work as intended. Not on paper, but tested through MITRE ATT&CK scenarios.

Learn more →
Continuous Vulnerability Management

Continuous Vulnerability Management

Not an annual snapshot but continuous insight. Risk-based prioritisation so your team knows what to fix first.

Learn more →
Managed Threat Intelligence

Managed Threat Intelligence

Only the intelligence that is relevant to your sector and environment. Monthly threat briefings for the CISO, IOC feeds for the SOC.

Learn more →
Purple Teaming

Purple Teaming

Red and blue team work together: simulate attacks, measure detection, improve detection rules based on MITRE ATT&CK mapping.

Learn more →
OT Security Monitoring

OT Security Monitoring

Your OT environment monitored 24/7, without impact on production processes. Passive monitoring of ICS/SCADA protocols.

Learn more →
Imminent Threat Exposure

Imminent Threat Exposure

Within 24-48 hours you know whether your organisation is exposed to active campaigns or already compromised. Dark web scan included.

Learn more →

Certified and recognised

ISO 27001
SOC 2
TF-CSIRT
Microsoft Partner
CrowdStrike Partner

Microsoft and CrowdStrike partner for technology and support. No sales targets on licences: our advice on your stack is independent.

Frequently asked questions

Frequently asked questions about MDR

What makes a good MDR provider for a Dutch organisation?
Look at five things: who assesses the alerts at night and where that person sits, which response times are contractually fixed, whether you can inspect and export the detection rules, where your log data lives and who can access it, and whether incident response is available immediately without a new contract. DEFION answers those five questions with analysts in Zoetermeer and Barcelona, P1 SLAs of 15/30/45 minutes, Detection-as-Code, monitoring inside your own tenant where possible and a DFIR team inside the SOC. A good MDR provider can be checked on each of those five points before you sign.
How does DEFION differ from a classic SOC or a product-MDR?
A classic SOC processes alerts; a product-MDR mainly watches its own product. DEFION has been independent since 2005, sells no security products and delivers MDR across your stack: Microsoft, CrowdStrike, Splunk or mixed. Our detection rules partly come from our own pentest and Red Team findings and live as code under version control. At DEFION, the attacker who tests your detection is the same organisation as the defender who has to see them.
Does our data stay under our control, and what does that mean in practice?
For Microsoft customers we monitor via Azure Lighthouse inside your own tenant: log data stays in your subscription, our access is least-privilege and visible in your audit logs, and when you leave you revoke the delegation without any migration. Azure is a US cloud; the point is not the nationality of the cloud but that you remain the owner of tenant, data and rules. For non-Microsoft stacks we fix retention, access and export contractually. Control means: you can revoke our access today and still reach all your data and detection rules tomorrow.
How do you measure detection time and noise filtering?
We report contractual SLAs for P1 incidents: MTTD within 15 minutes (from event to validated alert), MTTI within 30 minutes (to confirmed or dismissed threat) and MTTR within 45 minutes (to first containment action). Actual detection times, the number of alerts filtered by AI and analysts, and the escalation ratio appear in the monthly report and are visible during the Proof of Value, with the measurement definition alongside. We do not publish loose averages without a definition; you get the figures for your environment, with an explanation of how they were measured.
How does MDR help with NIS2, DORA and ISO 27001?
NIS2 requires an early warning within 24 hours and a notification within 72 hours; DORA requires demonstrable detection and response processes for ICT incidents; ISO 27001 requires logging, monitoring and incident management as controls. DEFION MDR provides the evidence: 24/7 monitoring with contractual SLAs, transparent detection logic, monthly reporting and an incident response team that can substantiate the notification. A 24-hour reporting duty is only achievable if someone sees the incident at night.
How fast are we live, and what happens on a P1 at night?
First visibility within days, full coverage typically within 1 to 2 weeks; fine-tuning detection rules for an enterprise environment takes about three months on average. On a P1 at three in the morning a DEFION analyst assesses the alert, performs containment within the SLA and calls the contact from your escalation matrix. If it escalates into an incident, the DFIR team that already sits in the SOC takes over. You only get called at night once an analyst has established that it matters.
What if we do not run Azure or Sentinel?
Then we integrate on your platform: CrowdStrike Falcon, Splunk, another SIEM or EDR, or a mixed environment. You get the same analysts, the same 24/7 coverage, the same P1 SLAs and the same Detection-as-Code; only the integration differs. You bring your existing licences. The own-tenant model is an advantage for Microsoft customers, not a condition for working with DEFION.
What is the difference between MDR and an in-house SOC?
An in-house 24/7 SOC needs 6 to 8 full-time analysts for continuous staffing, plus tooling, training and retention of scarce people. MDR delivers that staffing as a service, with fixed response times. It is a build-or-buy decision; for most organisations up to a few thousand employees, buying is faster and more predictable. A SOC is a team you have to staff; MDR is an outcome you can hold someone to.
Does DEFION MDR work for OT and industrial environments?
Yes. With OT Security Monitoring we passively monitor ICS/SCADA protocols such as Modbus, DNP3 and Profinet, without impact on production processes. Our analysts know the Purdue architecture and the threats specific to industrial environments. OT monitoring at DEFION never touches your production process, only the network mirror.

Find out in thirty minutes
whether MDR fits your stack

Tell us what you want to monitor and which platforms you already run. We will show you what track A or B looks like for your environment, what the SLAs mean in practice and how a Proof of Value works.

Independent since 2005 · Analysts in Zoetermeer and Barcelona · ISO 27001 · SOC 2 · TF-CSIRT