Attackers work outside office hours, and technology is better at that than people are. Our detection and response run automatically, day and night: an infected device is isolated within seconds, a hijacked account blocked immediately. The routine is handled by the technology; for critical and unusual incidents a specialist reviews on working days what happened, what we did, and how we stop it coming back.

Your basics are in order, or we have just sorted that together, and you want something to actually happen when things go wrong. Your insurer asks for detection and logging. Or you have an in-house IT person who runs the shop by day but sleeps at night.
We connect Microsoft Defender to your environment, and at the extended level Microsoft Sentinel as well. No extra software on the workplace: we use what is already in your Microsoft licence and switch it on properly.
What is normal behaviour for you? Which systems are critical? And above all: where may we intervene without calling first? We agree that boundary in advance, because that is where the speed comes from.
Detection runs without interruption. During an attack the technology immediately carries out the agreed measures, even in the middle of the night and at weekends. Because nobody is steering at that hour, those measures are agreed tightly in advance: isolate and block, not alert and wait.
Routine alerts are handled by the technology and appear in the monthly report. Critical and unusual incidents are reviewed by a specialist on working days: what happened, was the automatic response right, and which setting prevents a repeat? That last part is the work that counts, and it is exactly what an automated system does not do.
"We earn nothing from an incident. So we would rather it never happened, and otherwise that it was over by three in the morning."Martijn Mol, Remarx
Not the clock. Both levels detect and intervene automatically, day and night, and at both a person reviews it on working days. What differs is how far our view reaches and how long we keep it.
| Managed Detection & ResponseMicrosoft Defender | Managed Extended Detection & ResponseDefender plus Microsoft Sentinel | |
|---|---|---|
| What we see | Devices, accounts, email and cloud apps inside Microsoft | Also firewall, network, VPN, servers and equipment outside Microsoft |
| Detection and intervention | Automatic, day and night | Automatic, day and night |
| Human review | Critical and unusual, on working days | Critical and unusual, on working days |
| Log retention | 30 days | 90 days to several years |
| Detection rules | Microsoft standard | Plus custom rules and playbooks for your environment |
| Evidence for NIS2 and insurers | Limited | Yes, with a demonstrable retention period |
| Requires | Microsoft 365 Business Premium | Plus your own Azure subscription |
At the extended level Microsoft Sentinel runs in your own Azure environment. Data usage therefore appears on your invoice and not on ours; we configure it so that it stays low and review it every quarter. Your logs remain yours, even if you ever leave.
We monitor your Microsoft environment for attacks and intervene when something goes wrong. An infected device is isolated and a hijacked account blocked, within seconds and automatically. A specialist then assesses what happened and what is needed.
The technology runs day and night and intervenes automatically outside office hours. We do not staff a night shift: critical and unusual incidents are reviewed by a specialist on working days, and you get the full account the next working day. That is exactly why we configure the automated response more strictly than usual.
MDR covers everything inside Microsoft 365: devices, accounts, email and apps. The extended variant adds Microsoft Sentinel and with it sources beyond Microsoft, such as firewall, network and servers, with longer log retention and evidence for audits.
For MDR usually not: the necessary protection is already in Microsoft 365 Business Premium, a licence many organisations already hold. The extended variant adds Microsoft Sentinel; we then also watch your Sentinel consumption and keep it low.
Most providers put "24/7 SOC" above every package without saying who is awake. We prefer to be precise. At night and at weekends the technology does the work: detecting and intervening within seconds, without anyone having to make a call. There is no person alongside it, and we do not pretend otherwise. That is exactly why we configure the automatic measures more strictly than usual. Where a provider with a night shift can settle for an alert and "we will take a look", ours has to be closed off in advance: device isolated, account blocked, session revoked. On the next working day the full account is on the table, along with what we are changing so it does not come back. Does your production run around the clock, with someone who must be able to decide at three in the morning? Then you need a provider with shift cover, and we would rather say that now than afterwards.
Security leadership at board level. A full-time CISO easily costs € 10,000 to € 15,000 a month, if you can find one.
Read moreWhere does an attacker get in?. A security assessment shows where you are vulnerable: technically and organisationally.
Read moreWorkplace, support and Intune. Open the laptop, sign in, work.
Read moreNo account manager, no call centre. You speak directly with one of the founders. You tell us what's going on; we tell you honestly whether and how we can help. Even if the answer is 'you don't need us'.


On working days, via Teams or phone. Choose a slot in our calendar and get an instant confirmation.
Open the calendar Prefer to call? 085 060 9448 · Or send a message