At three in the morning the technology steps in. At nine a person looks at it.
Attackers work outside office hours, and technology is better at that than people are. Our detection and response run automatically, day and night: an infected device is isolated within seconds, a hijacked account blocked immediately. The routine is handled by the technology; for critical and unusual incidents a specialist reviews on working days what happened, what we did, and how we stop it coming back.

Sound familiar?
Your basics are in order, or we have just sorted that together, and you want something to actually happen when things go wrong. Your insurer asks for detection and logging. Or you have an in-house IT person who runs the shop by day but sleeps at night.
Situations in which clients end up with us
- Defender is switched on, but nobody looks at the alerts.
- A hacked mailbox was only discovered after three days.
- The insurer asks for detection with monitoring and you do not know whether you have it.
- You want security alongside your current IT provider, without replacing them.
- During an investigation it turns out the logs only go back thirty days.
Four steps, no surprises.
Connect
We connect Microsoft Defender to your environment, and at the extended level Microsoft Sentinel as well. No extra software on the workplace: we use what is already in your Microsoft licence and switch it on properly.
Tune
What is normal behaviour for you? Which systems are critical? And above all: where may we intervene without calling first? We agree that boundary in advance, because that is where the speed comes from.
Watch and intervene
Detection runs without interruption. During an attack the technology immediately carries out the agreed measures, even in the middle of the night and at weekends. Because nobody is steering at that hour, those measures are agreed tightly in advance: isolate and block, not alert and wait.
Review and improve
Routine alerts are handled by the technology and appear in the monthly report. Critical and unusual incidents are reviewed by a specialist on working days: what happened, was the automatic response right, and which setting prevents a repeat? That last part is the work that counts, and it is exactly what an automated system does not do.
What's included
- Detection and automatic intervention, day and night
- Devices isolated and accounts blocked within seconds
- Critical and unusual incidents reviewed by a specialist, on working days
- The full account of what happened, on the next working day
- Monthly report in language for the board, with an appendix for your IT person
- Works alongside your existing IT provider or in-house IT
- Quarterly meeting about what we saw and what can be improved
"We earn nothing from an incident. So we would rather it never happened, and otherwise that it was over by three in the morning."Martijn Mol, Remarx
The difference is what we can see.
Not the clock. Both levels detect and intervene automatically, day and night, and at both a person reviews it on working days. What differs is how far our view reaches and how long we keep it.
| Managed Detection & ResponseMicrosoft Defender | Managed Extended Detection & ResponseDefender plus Microsoft Sentinel | |
|---|---|---|
| What we see | Devices, accounts, email and cloud apps inside Microsoft | Also firewall, network, VPN, servers and equipment outside Microsoft |
| Detection and intervention | Automatic, day and night | Automatic, day and night |
| Human review | Critical and unusual, on working days | Critical and unusual, on working days |
| Log retention | 30 days | 90 days to several years |
| Detection rules | Microsoft standard | Plus custom rules and playbooks for your environment |
| Evidence for NIS2 and insurers | Limited | Yes, with a demonstrable retention period |
| Requires | Microsoft 365 Business Premium | Plus your own Azure subscription |
At the extended level Microsoft Sentinel runs in your own Azure environment. Data usage therefore appears on your invoice and not on ours; we configure it so that it stays low and review it every quarter. Your logs remain yours, even if you ever leave.
Frequently asked questions
What exactly is Managed Detection & Response?
We monitor your Microsoft environment for attacks and intervene when something goes wrong. An infected device is isolated and a hijacked account blocked, within seconds and automatically. A specialist then assesses what happened and what is needed.
Do you monitor 24 hours a day?
The technology runs day and night and intervenes automatically outside office hours. We do not staff a night shift: critical and unusual incidents are reviewed by a specialist on working days, and you get the full account the next working day. That is exactly why we configure the automated response more strictly than usual.
What is the difference between MDR and the extended variant?
MDR covers everything inside Microsoft 365: devices, accounts, email and apps. The extended variant adds Microsoft Sentinel and with it sources beyond Microsoft, such as firewall, network and servers, with longer log retention and evidence for audits.
Do we need expensive extra licences for this?
For MDR usually not: the necessary protection is already in Microsoft 365 Business Premium, a licence many organisations already hold. The extended variant adds Microsoft Sentinel; we then also watch your Sentinel consumption and keep it low.
We have no night shift. That is why our automation is stricter.
Most providers put "24/7 SOC" above every package without saying who is awake. We prefer to be precise. At night and at weekends the technology does the work: detecting and intervening within seconds, without anyone having to make a call. There is no person alongside it, and we do not pretend otherwise. That is exactly why we configure the automatic measures more strictly than usual. Where a provider with a night shift can settle for an alert and "we will take a look", ours has to be closed off in advance: device isolated, account blocked, session revoked. On the next working day the full account is on the table, along with what we are changing so it does not come back. Does your production run around the clock, with someone who must be able to decide at three in the morning? Then you need a provider with shift cover, and we would rather say that now than afterwards.
Your next step.
CISO as a Service
Security leadership at board level. A full-time CISO easily costs € 10,000 to € 15,000 a month, if you can find one.
Read moreSecurity Assessment & pentest
Where does an attacker get in?. A security assessment shows where you are vulnerable: technically and organisationally.
Read moreManaged Modern Workplace
Workplace, support and Intune. Open the laptop, sign in, work.
Read moreTwenty minutes with Martijn or Remy.
No account manager, no call centre. You speak directly with one of the founders. You tell us what's going on; we tell you honestly whether and how we can help. Even if the answer is 'you don't need us'.


Pick a time
On working days, via Teams or phone. Choose a slot in our calendar and get an instant confirmation.
Open the calendar Prefer to call? 085 060 9448 · Or send a message