DEFION in numbers
Five disciplines.
One partner.
No juggling five vendors for five problems. One team that covers your entire security posture, from advisory to 24/7 monitoring and crisis response.
Independent.
AI-accelerated.
20 years proven.
You get advice without a hidden sales agenda. DEFION doesn't sell products, only protection. That means our recommendations are always in your interest.
From boardroom to server room, 24/7 monitoring and AI-accelerated pentesting. One partner for your entire attack surface: IT, OT, and IoT.
About DEFION →
100+ specialists.
Two offices.
One team.
Zoetermeer and Barcelona. Real people, senior expertise. No offshore support, no call-center triage. When you call DEFION, you reach the engineer who can actually help.
Independent since 2005. Still driven by the people who founded it.




Faster detection.
Less noise.
Better decisions.
You only get alerts that matter. No flood of false positives, no overwhelmed security team. Our technology filters the noise, our experts make the calls.
The result: threats detected in minutes instead of days. And when it counts, there are always people ready who know what to do.
Alert within 4 minutes
No hours or days waiting for an alarm
Only what matters
Your team sees relevant alerts, not thousands
Pentest in 24 hours
First vulnerabilities same day, not after weeks
Experts who decide
No automated guesswork, real human judgment
What we see right now.
Week 21, 2026 · Updated May 22, 2026
Our TI team monitors 40+ sources 24/7. These are the most relevant threats for European organizations.
Netatalk AFP server: 8 CVEs published simultaneously, CVSS 9.9 heap overflow enables remote code execution with root escalation, NAS and OT networks at risk
Netatalk: 8 CVEs including CVSS 9.9 RCE with root escalation on AFP servers. NAS devices and OT/IT environments at risk. Action: update immediately to Netatalk 4.4.3+ and scan for AFP services on port 548.
May 22, 2026 · Confidence: High
Read more →APT73 and Qilin strike 4 EU/DACH organizations in 24 hours: Friday deployment risk elevated for European manufacturing sector
APT73 and Qilin: 4 EU/DACH victims in 24 hours (Germany x2, Austria, North Macedonia). Friday deployment risk elevated for EU manufacturing. Infostealers (Lumma/RedLine) active on victim infrastructure. Action: elevate monitoring and verify offline backups.
May 22, 2026 · Confidence: High
Read more →BitLocker YellowKey bypass (NCSC-2026-0165): PoC publicly available, recovery environment weakness enables access to encrypted drives
BitLocker YellowKey bypass (NCSC-2026-0165): PoC now public. Recovery environment weakness allows access to encrypted drives. Affects all enterprises relying on BitLocker. Action: patch Windows endpoints immediately and audit unmanaged device inventory.
May 22, 2026 · Confidence: High
Read more →We speak your language.
Newsroom
AZ and DEFION Security: Official Supplier for Optimal Data Protection
AZ and DEFION enter into a multi-year strategic partnership as Official Supplier to strengthen the club's digital resilience. DEFION protects the valuable data AZ uses for performance on and off the pitch.
CVE-2026-31431 ("Copy Fail"): Critical Linux Privilege Escalation Vulnerability Explained
CVE-2026-31431 ("Copy Fail") is a Linux kernel vulnerability enabling stealthy privilege escalation to root. Learn about the impact, affected systems, and mitigation steps.
SURF Deployment: DEFION and DTX Secure 75+ Education and Research Institutions
DTX and DEFION begin rolling out MDR services for SURF. More than 75 Dutch universities, polytechnics and vocational colleges receive 24/7 protection against cyberattacks.
Ready to make your
security AI-proof?
Talk to one of our experts. No obligations, no sales pitch: an honest conversation about your situation.
® 










