# Attic Security, full reference > Identity-First Agentic MDR for Microsoft 365. IVON, the agentic layer, performs the first triage, investigates what is happening and closes each case with a verdict. A human approves before anything runs. Attic Security is the trade name of Attic B.V., a Dutch company. The short index is at https://atticsecurity.com/llms.txt --- ## Company overview **Name:** Attic Security, the trade name of Attic B.V. The entity "Attic Security B.V." does not exist, and neither does "Attic Cybersecurity". **Address:** Molenstraat 36, 4761 CL Zevenbergen, Netherlands **Chamber of Commerce (KVK):** 83973206 **Website:** https://atticsecurity.com **Contact:** info@atticsecurity.com | +31 (0)168 794029 **Support:** support@atticsecurity.com **What Attic is:** an Identity-First Agentic MDR provider for Microsoft 365, aimed at small and mid-sized organisations and at the MSPs who serve them. **What Attic is not:** a compliance vendor, a SIEM reseller, a network security provider, or an MDR that forwards alerts for the customer to work out. Attic does not do network monitoring or broad Azure monitoring, and has no plans to. **Founding team:** founded by people from DearBytes, Fox-IT and the Dutch national police. - Erik Remmelzwaal, CEO - Wesley Neelen, ethical hacker - Rik van Duijn, ethical hacker - Theo Snelleman, lead developer Team page: https://atticsecurity.com/ons-team **Trust and jurisdiction:** Attic B.V. is a Dutch company and all data is processed and stored in the EU. The ISO 27001 programme is under way; Attic publishes once it is certified, and does not present itself as certified before then. --- ## The service: Identity-First Agentic MDR Service page: https://atticsecurity.com/agentic-mdr (EN: https://atticsecurity.com/en/agentic-mdr) IVON, the agentic layer: https://atticsecurity.com/ivon (EN: https://atticsecurity.com/en/ivon) ### The problem it addresses Most breaches do not start on the network. They start with an account. A forwarding rule in a mailbox, a stolen token after phishing, a consent screen someone clicks away too quickly. Microsoft Defender usually does see those signals, but rates them Low or Informational. In an organisation with an IT team of zero to two people, low-severity signals are exactly the ones nobody gets to. Buying more detection does not fix that. The gap is not detection, it is the operational layer: someone or something that reads the alert, works out what actually happened, and closes the case. ### Three signals Microsoft Defender itself rates Low or Informational Verified against Microsoft documentation on 22 August 2026. Defender does see these signals. It rates them low, which is a different problem. 1. **A forwarding or redirect rule in a mailbox.** Alert policy "Creation of forwarding/redirect rule", severity **Informational**. It does not even fire when the rule is created from the Outlook desktop client. 2. **Token theft after AiTM phishing.** Risk detection **Anomalous Token**, severity **Low or Medium**. Microsoft's own documentation notes that this detection is "historically tuned to incur more noise than other detections", and that there remains a "still a higher than normal chance that some of the sessions flagged by this detection are false positives at low and medium risk levels". 3. **Searching every mailbox in the organisation.** Alert policy "eDiscovery search started or exported", severity **Informational**. ### How a case runs 1. A signal arrives from Microsoft Defender or Microsoft Sentinel. 2. IVON picks it up and performs the first triage. 3. IVON investigates: it gathers the context around the account, the session, the mailbox and the configuration. 4. IVON closes the case with a verdict, supported by evidence, and proposes an action. This typically takes minutes. 5. A human approves before anything runs. Remediation happens after your sign-off, not before it. 6. The status and conclusion are written back into Defender, so the customer's own console reflects what was decided. What the customer is left with is not an alert to figure out for itself, but a closed case with a trail it can read back. ### Escalation Attic does not call. Notifications and escalations always run over email, webhook or push notification in the Attic app, 24 hours a day. When IVON is uncertain, the case escalates to an analyst. ### Reporting - For an escalated incident, the timeline is in the incident report. - Monthly, the customer receives a total overview of processed alerts. - On request, Attic supplies the full triage flow per alert as a report. - Status and conclusion also go back into Defender. ### Onboarding and consent Self-service onboarding, live within 5 minutes, Microsoft 365-native, with no extra agents on endpoints. At onboarding Attic asks in one go for the permissions belonging to the chosen service level: read-only, or write for auto-remediation. There is no separate consent prompt at the moment of the first remediation. ### Continuous hardening Alongside detection and response, the configuration is brought to a desired state theme by theme, inspired by the CIS benchmark and supplemented with Attic's own and external research. After that, continuous drift detection with one-click fixes. --- ## Products and pricing All products protect Microsoft 365 environments. Prices exclude VAT. 10% discount on annual payment. Calculator and full specification: https://atticsecurity.com/pricing (EN: https://atticsecurity.com/en/pricing) The line-up sold directly is Attic Free, Attic Fixer and Attic MDR. There are no editions to choose between within Attic MDR: one tiered per-user model covers it. ### Attic MDR, the service including IVON **Price:** from €30 per month for 1 to 5 users, then €6 per user per month, with the rate per user declining as the user count rises. **Activation:** self-service, within 5 minutes **URL:** https://atticsecurity.com/agentic-mdr | Users | Per month | Per month on annual payment | |---|---|---| | 1 to 5 | €30 | €27 | | 25 | €150 | €135 | | 50 | €275 | €247.50 | | 100 | €400 | €360 | | 250 | €550 | €495 | **What is included:** - Everything in Attic Fixer - 24x7 detection and response across the Microsoft 365 environment - IVON: alert follow-up, investigation and a verdict with evidence per incident, typically within minutes - A remediation proposal, executed after your sign-off - Escalation to an analyst when IVON is uncertain - Microsoft Sentinel integration - Three months of log retention - The standard allowance for incident handling **No minimum purchase and no unit minimum.** Pricing is per user, from a single user upwards. ### IVON capacity extensions Attic MDR includes a standard allowance for incident handling. If that is structurally too little, it can be extended with a monthly bundle. A bundle **adds** capacity on top of the standard allowance rather than replacing it, so +2x means 2 times the standard allowance added to what is already included. | Bundle | Adds | Per user per month | Example at 25 users | |---|---|---|---| | +2x | 2 times the standard allowance | €3.50 | €87.50 | | +5x | 5 times the standard allowance | €8 | €200 | | +10x | 10 times the standard allowance | €14 | €350 | | +20x | 20 times the standard allowance | €24 | €600 | | +50x | 50 times the standard allowance | €50 | €1,250 | The per-user rate for a bundle drops in two steps above 500 and above 1,000 users. +2x and +5x can be ordered directly; +10x, +20x, +50x run through a quote. For occasional peaks rather than a structural increase there are one-off Incident Packs, which do not expire. Prices on request. Going over the allowance without a bundle or pack is billed afterwards at €3.50 per additional handled incident. ### Attic Fixer, hardening and configuration management **Price:** €120 per month, €108 per month on annual payment. Incl. 50 users, +€1 per extra user. **Activation:** 5 minutes **URL:** https://atticsecurity.com/fixer Attic Fixer runs automated security checks on the Microsoft 365 configuration, based on CIS benchmarks and Attic's own threat research. When a misconfiguration is found, Attic proposes a fix that is applied with one click after explicit approval, and then keeps watching for drift. It includes login activity monitoring and the phishing protection from Attic Free. It does not include the 24x7 service or IVON. ### Attic Free, phishing protection **Price:** free, unlimited users, no payment details **Activation:** 5 minutes **URL:** https://atticsecurity.com/free Real-time detection of fake Microsoft 365 login pages, also known as Adversary-in-the-Middle (AiTM) attacks. When an employee lands on a fake login page, Attic shows a red warning screen before any credentials are entered. On genuine Microsoft login pages an authenticity seal is shown. Administrators are notified by email. Available as a browser extension for Chrome and Edge, and as a validation app in Microsoft Teams. Standard MFA does not protect against AiTM, because the attacker intercepts the password and the MFA code in real time and takes over the session. ### Attic Bouncer **URL:** https://atticsecurity.com/bouncer Identity threat detection and response: monitoring of Microsoft 365 login activity, detection of suspicious sign-in attempts, and security awareness training. Since July 2026 Bouncer is no longer part of the directly sold line-up and has no public price. The product page remains, and the product remains available through the MSP and partner channel. For direct customers its monitoring functionality is part of Attic Fixer and Attic MDR. --- ## Getting started ### Free one-time IVON incident investigation **URL:** https://atticsecurity.com/incidentonderzoek (EN: https://atticsecurity.com/en/incident-investigation) **Terms:** https://atticsecurity.com/incidentonderzoek-voorwaarden (EN: https://atticsecurity.com/en/incident-investigation-terms) A free, one-time investigation of your own Microsoft 365 environment, available from 1 September 2026. It starts from the Microsoft admin consent screen and asks for read permissions only. It is not a trial period and not a way to start before the launch; it is a lower step for organisations that would rather see one run on their own environment than sign a contract first. ### 14-day trial of Attic MDR **URL:** https://atticsecurity.com/trial (EN: https://atticsecurity.com/en/trial) A trial period of 14 days on Attic MDR. It is activated from the pricing page, not from the trial page itself. The cart starts at zero, so no payment details are required at the start. Pricing page: https://atticsecurity.com/pricing ### Talk to someone - Book a meeting: https://atticsecurity.com/meeting - Contact: https://atticsecurity.com/contact - Incident response, if something is happening right now: https://atticsecurity.com/incident-response --- ## Target audiences ### SMBs (MKB) **URL:** https://atticsecurity.com/mkb Small and mid-sized organisations are attractive targets precisely because they rarely have a dedicated security team. Attic is built for an IT team of zero to two people: self-service activation, no security expertise required, and a verdict rather than an alert queue. ### MSPs and IT partners **URL:** https://atticsecurity.com/msp **Partner trial:** https://atticsecurity.com/msp-trial IT service providers can deliver Attic to their customers, managing all customer tenants from a single partner portal, using the existing CSP relationship with Microsoft. There is no minimum purchase and no unit minimum, which matters for a partner whose book consists of small customers. ### Government and semi-public sector **URL:** https://atticsecurity.com/overheid (EN: https://atticsecurity.com/en/overheid) Dutch-language support, EU data processing, and the operational layer that public-sector security requirements expect. Attic does not certify anyone and does not make anyone compliant. --- ## Threat coverage - **Business Email Compromise (BEC):** the pillar category, covering CEO fraud, invoice fraud, vendor fraud and account takeover. Attackers impersonate trusted parties, directors, colleagues or suppliers, and exploit trust, authority and time pressure rather than purely technical weaknesses. With AI, the messages now arrive in flawless Dutch and include voice and video deepfakes. Average loss per incident: €118,000 (FBI IC3, 2024). Cyber insurance often does not cover BEC if MFA was missing. - **CEO fraud, a sub-variant of BEC:** attackers impersonate executives to authorise urgent payments. Pathé Nederland lost €19.2 million; Jewometaal Rotterdam lost €11.4 million through a voice-deepfake phone call; Elco in Helmond went bankrupt after a €771,760 loss. - **Phishing and AiTM (Adversary-in-the-Middle):** fake login pages that capture credentials and MFA codes in real time and take over the session. The primary entry point into BEC. - **Token hijacking:** stealing and reusing authentication tokens to reach accounts without a password. - **Ransomware:** software that encrypts files and demands a ransom, typically entering through phishing. - **Domain hijacking:** taking control of a domain to redirect traffic or impersonate an organisation. - **Brute force and credential stuffing:** automated password guessing using leaked credential databases. - **Website spoofing:** fake copies of legitimate websites built to harvest credentials. Threat pages: - Business Email Compromise (BEC), pillar: https://atticsecurity.com/bec (EN: https://atticsecurity.com/en/bec) - CEO fraud: https://atticsecurity.com/ceo-fraude (EN: https://atticsecurity.com/en/ceo-fraud) - Phishing: https://atticsecurity.com/phishing (EN: https://atticsecurity.com/en/phishing) - Adversary-in-the-Middle (AiTM): https://atticsecurity.com/adversary-in-the-middle (EN: https://atticsecurity.com/en/adversary-in-the-middle) - Ransomware: https://atticsecurity.com/ransomware (EN: https://atticsecurity.com/en/ransomware) - Domain hijacking: https://atticsecurity.com/domain-hijacking (EN: https://atticsecurity.com/en/domain-hijacking) - Website spoofing: https://atticsecurity.com/website-spoofing (EN: https://atticsecurity.com/en/website-spoofing) - DNS and domain security: https://atticsecurity.com/dns-domein-security (EN: https://atticsecurity.com/en/dns-domein-security) ### NCSC BEC publication, April 2026 Attic Security is named as a co-author of the official publication on Business Email Compromise by the Dutch National Cyber Security Centre (NCSC), released in April 2026 in two parts: 1. **"Business E-mail Compromise (BEC), praktische handvatten voor het mkb"**, 15 pages, non-technical, for SMB directors and managers: https://atticsecurity.com/documents/nl/NCSC_BEC_Praktische-handvatten-mkb.pdf 2. **"Business E-mail Compromise (BEC), technisch advies"**, 21 pages, structured along MITRE ATT&CK, with 19 concrete measures for hardening Microsoft 365 and Outlook, for IT providers and MSSPs: https://atticsecurity.com/documents/nl/NCSC_BEC_Technisch-advies.pdf The publication was produced through **Cyclotron**, a Dutch public-private intelligence-sharing partnership under the Nederlandse Cybersecuritystrategie 2022 to 2028. The other co-authors are **Orange Cyberdefense, Invictus and Tesorion**. The 19 measures cover the full MITRE chain from reconnaissance through to impact, each with a priority, impact and effort rating. --- ## NIS2 and the Cyberbeveiligingswet **URLs:** https://atticsecurity.com/nis2 (EN: https://atticsecurity.com/en/nis2) ### Regulatory context NIS2 is the EU Network and Information Security Directive 2, in force across the European Union since 17 October 2024. It replaces the original NIS directive from 2016 and expands the scope from eight sectors to eighteen. Each member state transposes the directive into national law. The Dutch transposition is the Cyberbeveiligingswet. The Rijksinspectie Digitale Infrastructuur (RDI) and sectoral regulators supervise enforcement. ### Who is in scope An organisation falls under NIS2 when three conditions are all met: 1. It operates in one of the eighteen designated sectors. 2. It has 50 or more employees, or an annual turnover of €10 million or more. 3. It provides goods or services in or to the European Union. The eighteen sectors include energy, transport, banking and financial market infrastructure, healthcare, drinking water and waste water, digital infrastructure (DNS, TLDs, data centres, CDNs, trust services), managed service providers, managed security service providers, public administration, space, postal services, waste management, food production, chemicals, research, and the manufacturing of medical devices, electronics, machinery and motor vehicles. NIS2 distinguishes *essential* entities (proactive supervision, higher fines) from *important* entities (reactive supervision, lower fines). The underlying obligations are identical for both. Organisations that are not themselves in scope still commonly face NIS2-level security requirements through their customer contracts, because in-scope organisations are required to manage supply-chain risk. ### Article 21: the ten categories of security measures Article 21 sets out ten mandatory categories of security measures that every in-scope organisation must implement proportionally to its risk profile, and must be able to demonstrate. 1. Risk analysis and information security policy 2. Incident handling 3. Business continuity, backups, crisis management 4. Supply chain security 5. Security in acquisition, development and maintenance 6. Assessment of the effectiveness of security measures 7. Basic cyber hygiene and security training 8. Cryptography and encryption 9. Human resources security, access control, asset management 10. Multi-factor authentication and secure communications ### Article 23: the reporting cascade For significant incidents, NIS2 requires a three-phase cascade: - **Phase 1, early warning, within 24 hours:** initial notification with the basic facts. - **Phase 2, incident notification, within 72 hours:** structured update with an initial severity assessment, impact and indicators of compromise. - **Phase 3, final report, within one month:** full reconstruction covering root cause, timeline, measures taken and lessons learned. An incident is significant when it causes serious disruption, meaningful financial damage, or impact on other organisations or individuals. ### Penalties - **Essential entities:** up to €10 million or 2% of global annual turnover, whichever is higher. - **Important entities:** up to €7 million or 1.4% of global annual turnover, whichever is higher. - **Non-financial sanctions:** temporary suspension of certifications or authorisations, public disclosure of the breach, and a temporary ban on executives holding management positions. NIS2 introduces personal liability for management in cases of serious negligence. ### How Attic relates to this **Attic does not make an organisation compliant and does not certify anyone.** What Attic does cover is the part the law expects operationally: actually handling incidents, so they can be reported in time. Most organisations already own Microsoft 365 licensing that includes the tooling to implement Article 21 on paper: Secure Score, Defender, Sentinel, Entra ID, Intune, Purview, Compliance Manager. What the licence does not include is the operational layer, the team or system that reads the alerts, investigates the anomalies and records the evidence. That is where Attic sits. Running an in-house SOC is out of financial reach for most European SMBs. An experienced SOC analyst costs €90,000 to €140,000 per year, and round-the-clock coverage needs at least three of them. Attic delivers that function as a service, through automation rather than headcount. In practice this touches incident handling (measure 2), basic cyber hygiene and training (measure 7), access control (measure 9), risk management and the assessment of effectiveness (measures 1, 5, 6), and the Article 23 reporting cascade: during a significant incident, the timeline and reconstruction come out of the incident report. Whether any of that is sufficient for a given organisation is a question for that organisation and its supervisor, not for Attic. --- ## Integrations and platforms **Primary platform:** Microsoft 365, all business subscriptions. - Microsoft Defender, as the source of signals - Microsoft Sentinel, for the 24x7 service - Browser extensions for Google Chrome and Microsoft Edge - Attic mobile app for iOS and Android - Microsoft Teams integration, the validation app - WordPress plugin - Configuration checks inspired by the CIS benchmark Plugins and apps: https://atticsecurity.com/plug-ins-apps --- ## Trust, privacy and data - **AVG and GDPR:** Attic processes personal data as a processor for its customers. Privacy statement: https://atticsecurity.com/privacy (EN: https://atticsecurity.com/en/privacy) - **Sub-processors:** published and kept current: https://atticsecurity.com/sub-verwerkers (EN: https://atticsecurity.com/en/sub-processors) - **Data location:** all data is processed and stored in the EU. - **Jurisdiction:** Attic B.V. is a Dutch company. - **ISO 27001:** the programme is under way. Attic publishes once it is certified and does not claim certification before then. - **CIS benchmark:** the configuration checks are based on Center for Internet Security benchmarks, supplemented with Attic's own research. --- ## Statistics with a named source Figures without a verifiable source have deliberately been left out of this file. - 3 in 4 Dutch citizens encountered attempted cybercrime in 2024 (Alert Online, Ministry of Economic Affairs) - 77% of Dutch SMBs were hit by cybercrime in the preceding two years (Motivaction and Vodafone, 2024) - 1 in 5 business owners suffered direct damage from a cyber attack in 2024 (ABN AMRO and NOS) - Average loss per BEC incident: €118,000 (FBI IC3, 2024) --- ## Resources - **Blog:** https://atticsecurity.com/blog - **Security alerts from our own research:** https://atticsecurity.com/alerts - **Resources and downloads:** https://atticsecurity.com/resources - **FAQ:** https://atticsecurity.com/faq (EN: https://atticsecurity.com/en/faq) - **Knowledge base and product documentation:** https://hub.atticsecurity.com/resources/faqs - **Triage tool:** https://atticsecurity.com/triage-tool - **Team:** https://atticsecurity.com/ons-team - **For investors:** https://atticsecurity.com/investor --- ## Languages Dutch is the default locale and carries no URL prefix. English lives under the /en/ prefix. Product pages, threat pages and legal documents exist in both. - Dutch homepage: https://atticsecurity.com/ - English homepage: https://atticsecurity.com/en/ --- ## Legal - Terms and conditions: https://atticsecurity.com/voorwaarden (EN: https://atticsecurity.com/en/terms) - Privacy statement: https://atticsecurity.com/privacy (EN: https://atticsecurity.com/en/privacy) - Cookie policy: https://atticsecurity.com/cookiebeleid (EN: https://atticsecurity.com/en/cookie-policy) - Sub-processors: https://atticsecurity.com/sub-verwerkers (EN: https://atticsecurity.com/en/sub-processors) - Terms for the IVON incident investigation: https://atticsecurity.com/incidentonderzoek-voorwaarden (EN: https://atticsecurity.com/en/incident-investigation-terms)