# Attic Cybersecurity > Automated Microsoft 365 security for SMBs, MSPs, and government organizations. Dutch company, founded by ethical hackers. 100% European. ## Company - Name: Attic Cybersecurity (Attic BV) - Location: Zevenbergen, Netherlands - Website: https://atticsecurity.com - English site: https://atticsecurity.com/en/ - Contact: info@atticsecurity.com | +31 (0)168 794029 - Founders: Erik Remmelzwaal (CEO), Wesley Neelen (Ethical Hacker), Rik van Duijn (Ethical Hacker), Theo Snelleman (Lead Developer) ## Products All products protect Microsoft 365 environments. Tiered: Free → Bouncer → Fixer → MDR. ### Attic Free — Phishing Protection - Free, unlimited users, no credit card - Detects fake Microsoft 365 login pages (AiTM attacks) in real-time - Red warning screen before credentials are entered on fake pages - Green authenticity seal on genuine Microsoft login pages - URL: https://atticsecurity.com/free ### Attic Bouncer — Identity Threat Detection & Response - From €30/month (€27/month yearly) - Login activity monitoring, brute-force and credential stuffing detection - Security awareness training for employees - URL: https://atticsecurity.com/bouncer ### Attic Fixer — Cloud Security Configuration Management - From €120/month (€108/month yearly) - 100+ automated security checks based on CIS benchmarks - One-click fixes after approval - URL: https://atticsecurity.com/fixer ### Attic MDR — Managed Detection & Response - From €300/month (€270/month yearly) - 24/7 monitoring, automated incident response - Microsoft Sentinel integration, NIS2 compliance support - URL: https://atticsecurity.com/mdr ## Target Audiences - SMBs (MKB): https://atticsecurity.com/mkb - MSPs & IT Partners: https://atticsecurity.com/msp - Government: https://atticsecurity.com/overheid ## Threat Knowledge Base Each page explains how the attack works, how to recognise it, and how Attic defends against it: - Business Email Compromise (BEC): https://atticsecurity.com/bec — pillar page; Attic is named co-author of the official NCSC publication "Business E-mail Compromise — Praktische handvatten voor het mkb" (April 2026), together with Orange Cyberdefense, Invictus and Tesorion. EN mirror: https://atticsecurity.com/en/bec - CEO Fraud (sub-variant of BEC): https://atticsecurity.com/ceo-fraude - Phishing: https://atticsecurity.com/phishing - Adversary-in-the-Middle (AiTM): https://atticsecurity.com/adversary-in-the-middle - Ransomware: https://atticsecurity.com/ransomware - Domain Hijacking: https://atticsecurity.com/domain-hijacking - Website Spoofing: https://atticsecurity.com/website-spoofing - Attic for Microsoft 365: https://atticsecurity.com/attic-for-microsoft365 - DNS & Domain Security: https://atticsecurity.com/dns-domein-security ## NIS2 & Cyberbeveiligingswet Attic is positioned as the operational security layer for Microsoft 365 environments that need to demonstrate NIS2 compliance. The Dutch transposition of NIS2 is the Cyberbeveiligingswet, expected to enter into force in 2026. - NIS2 landing page (NL): https://atticsecurity.com/nis2 - NIS2 landing page (EN): https://atticsecurity.com/en/nis2 Key NIS2 facts the pages cover: - NIS2 directive in force across the EU since 17 October 2024 - Eighteen designated sectors, expanded from eight under NIS-1 - Scope threshold: 50+ employees or €10M+ annual turnover - Two entity classes: essential (proactive supervision) and important (reactive supervision) - Article 21 of the directive defines ten mandatory security measure categories - Article 23 reporting cascade: early warning within 24 hours, incident notification within 72 hours, final report within one month - Maximum fines: €10M or 2% global turnover (essential), €7M or 1.4% (important) - Personal liability for management in cases of serious non-compliance How Attic maps to Article 21: - Attic FREE: basic cyber hygiene, anti-phishing user warnings (measure 7) - Attic BOUNCER: access control, session monitoring, incident detection (measures 9, 2) - Attic FIXER: risk management, CIS-benchmark hardening, effectiveness assessment (measures 1, 5, 6) - Attic MDR: 24/7 SOC, incident handling, reporting-obligation evidence, long-term log retention (measures 2, 3, and the Article 23 reporting cascade) ## Key Statistics (2024) - 3 in 4 Dutch citizens encountered cybercrime attempts in 2024 (Alert Online / Min. van EZ) - 77% of SMBs were hit by cybercrime in the past two years (Motivaction/Vodafone 2024) - 1 in 5 business owners suffered direct damage from a cyber attack in 2024 (ABN AMRO / NOS) ## Key Pages - Pricing: https://atticsecurity.com/pricing - Free Trial: https://atticsecurity.com/trial - FAQ: https://atticsecurity.com/faq - Blog: https://atticsecurity.com/blog - Security Alerts: https://atticsecurity.com/alerts - Incident Response: https://atticsecurity.com/incident-response - Contact: https://atticsecurity.com/contact - Book a Meeting: https://atticsecurity.com/meeting - Team: https://atticsecurity.com/ons-team - Triage Tool: https://atticsecurity.com/triage-tool - Plugins & Apps: https://atticsecurity.com/plug-ins-apps ## Compliance AVG/GDPR compliant. NIS2 ready (MDR tier). CIS benchmark-based checks. All data stays in the EU. ## Full Details For comprehensive product, pricing, and company information see: https://atticsecurity.com/llms-full.txt