Home ServicesMicrosoft 365 Health CheckSecurity AssessmentManaged Cloud (Azure)Managed Modern WorkplaceManaged Detection & ResponseCISO as a ServiceCTO as a Service Pricing About News Contact Straight answers Book 20 minutes
NLEN
Home/Services/Managed Detection & Response
InsightManagementMonitoringDirection

At three in the morning the technology steps in. At nine a person looks at it.

Attackers work outside office hours, and technology is better at that than people are. Our detection and response run automatically, day and night: an infected device is isolated within seconds, a hijacked account blocked immediately. The routine is handled by the technology; for critical and unusual incidents a specialist reviews on working days what happened, what we did, and how we stop it coming back.

Discuss your situation Pricing
Secondsto automatic isolation, day and night
Working dayshuman analysis and follow-up
MicrosoftDefender and Sentinel, no extra agent
From € 6p/employee p/mo + € 250 base · guide price
Security specialist with a headset behind three screens with dashboards
Who it's for

Sound familiar?

Your basics are in order, or we have just sorted that together, and you want something to actually happen when things go wrong. Your insurer asks for detection and logging. Or you have an in-house IT person who runs the shop by day but sleeps at night.

Situations in which clients end up with us

  • Defender is switched on, but nobody looks at the alerts.
  • A hacked mailbox was only discovered after three days.
  • The insurer asks for detection with monitoring and you do not know whether you have it.
  • You want security alongside your current IT provider, without replacing them.
  • During an investigation it turns out the logs only go back thirty days.
How it works

Four steps, no surprises.

01

Connect

We connect Microsoft Defender to your environment, and at the extended level Microsoft Sentinel as well. No extra software on the workplace: we use what is already in your Microsoft licence and switch it on properly.

02

Tune

What is normal behaviour for you? Which systems are critical? And above all: where may we intervene without calling first? We agree that boundary in advance, because that is where the speed comes from.

03

Watch and intervene

Detection runs without interruption. During an attack the technology immediately carries out the agreed measures, even in the middle of the night and at weekends. Because nobody is steering at that hour, those measures are agreed tightly in advance: isolate and block, not alert and wait.

04

Review and improve

Routine alerts are handled by the technology and appear in the monthly report. Critical and unusual incidents are reviewed by a specialist on working days: what happened, was the automatic response right, and which setting prevents a repeat? That last part is the work that counts, and it is exactly what an automated system does not do.

What's included

  • Detection and automatic intervention, day and night
  • Devices isolated and accounts blocked within seconds
  • Critical and unusual incidents reviewed by a specialist, on working days
  • The full account of what happened, on the next working day
  • Monthly report in language for the board, with an appendix for your IT person
  • Works alongside your existing IT provider or in-house IT
  • Quarterly meeting about what we saw and what can be improved

"We earn nothing from an incident. So we would rather it never happened, and otherwise that it was over by three in the morning."Martijn Mol, Remarx

Two levels

The difference is what we can see.

Not the clock. Both levels detect and intervene automatically, day and night, and at both a person reviews it on working days. What differs is how far our view reaches and how long we keep it.

Managed Detection & ResponseMicrosoft DefenderManaged Extended Detection & ResponseDefender plus Microsoft Sentinel
What we seeDevices, accounts, email and cloud apps inside MicrosoftAlso firewall, network, VPN, servers and equipment outside Microsoft
Detection and interventionAutomatic, day and nightAutomatic, day and night
Human reviewCritical and unusual, on working daysCritical and unusual, on working days
Log retention30 days90 days to several years
Detection rulesMicrosoft standardPlus custom rules and playbooks for your environment
Evidence for NIS2 and insurersLimitedYes, with a demonstrable retention period
RequiresMicrosoft 365 Business PremiumPlus your own Azure subscription

At the extended level Microsoft Sentinel runs in your own Azure environment. Data usage therefore appears on your invoice and not on ours; we configure it so that it stays low and review it every quarter. Your logs remain yours, even if you ever leave.

Frequently asked questions

What exactly is Managed Detection & Response?

We monitor your Microsoft environment for attacks and intervene when something goes wrong. An infected device is isolated and a hijacked account blocked, within seconds and automatically. A specialist then assesses what happened and what is needed.

Do you monitor 24 hours a day?

The technology runs day and night and intervenes automatically outside office hours. We do not staff a night shift: critical and unusual incidents are reviewed by a specialist on working days, and you get the full account the next working day. That is exactly why we configure the automated response more strictly than usual.

What is the difference between MDR and the extended variant?

MDR covers everything inside Microsoft 365: devices, accounts, email and apps. The extended variant adds Microsoft Sentinel and with it sources beyond Microsoft, such as firewall, network and servers, with longer log retention and evidence for audits.

Do we need expensive extra licences for this?

For MDR usually not: the necessary protection is already in Microsoft 365 Business Premium, a licence many organisations already hold. The extended variant adds Microsoft Sentinel; we then also watch your Sentinel consumption and keep it low.

We have no night shift. That is why our automation is stricter.

Most providers put "24/7 SOC" above every package without saying who is awake. We prefer to be precise. At night and at weekends the technology does the work: detecting and intervening within seconds, without anyone having to make a call. There is no person alongside it, and we do not pretend otherwise. That is exactly why we configure the automatic measures more strictly than usual. Where a provider with a night shift can settle for an alert and "we will take a look", ours has to be closed off in advance: device isolated, account blocked, session revoked. On the next working day the full account is on the table, along with what we are changing so it does not come back. Does your production run around the clock, with someone who must be able to decide at three in the morning? Then you need a provider with shift cover, and we would rather say that now than afterwards.

Where to next?

Your next step.

Or book 20 minutes now
Let's talk

Twenty minutes with Martijn or Remy.

No account manager, no call centre. You speak directly with one of the founders. You tell us what's going on; we tell you honestly whether and how we can help. Even if the answer is 'you don't need us'.

Martijn MolRemy Cavo

Pick a time

On working days, via Teams or phone. Choose a slot in our calendar and get an instant confirmation.

Open the calendar Prefer to call? 085 060 9448 · Or send a message