Hunt & Hackett
Hunt & Hackett is a privately held Dutch cybersecurity firm that delivers threat-driven Managed Detection and Response, Incident Response, Threat Hunting, and security assessments to European enterprises and governments, built on Google Cloud SecOps and a proprietary cloud-native IR lab.
- Company typePrivate
- Founded2020
- HeadquartersThe Hague, Netherlands
- Headcount51–100
- GTM typeB2B
- OfferingServices
What Hunt & Hackett does
Hunt & Hackett is a privately held Dutch cybersecurity services firm founded in 2020 and headquartered in The Hague, Netherlands. It provides threat-driven managed detection and response (MDR), incident response (IR) and retainer (IRR), breach and attack simulation (BAS), threat hunting (TH), and security program gap assessment (SPGA) services to European enterprises and governments. The company was founded by Ronald Prins (co-founder of Fox-IT) and Jurjen Harskamp (former Fox-IT executive) and built a team with deep offensive and DFIR pedigrees from Fox-IT and similar organizations.
The core technology stack is the Google Cloud Security Operations (SecOps) platform, integrating SIEM, SOAR, VirusTotal, Mandiant threat intelligence, and Google Cloud Threat Intelligence. On top of this, Hunt & Hackett has built a proprietary cloud-native Incident Response Lab using Infrastructure-as-Code (Terraform, Packer) that provisions investigation environments within 15 minutes and completes automated forensic data acquisition and processing within two hours, integrating open-source DFIR tools such as the Dissect framework (originating from Fox-IT), Velociraptor, SharpHound, WinPmem, AVML, and Timesketch. The firm continuously monitors 400+ APT groups and 113 ransomware actor groups, feeding sector-based, country-based, and threat-actor-specific intelligence content that is delivered through a Members Portal, annual trend reports, and CyberConnect roundtables.
The business model is enterprise subscription and retainer based. MDR, IRR, and Threat Hunting are recurring subscription services; BAS and SPGA are professional-services engagements; sector/country/actor intelligence and the Members Portal are content-driven adjuncts. Pricing is custom and quote-based, with annual billing cadence and no public pricing tiers. Go-to-market is direct enterprise sales targeting CISOs across verticals including agriculture, energy, maritime, manufacturing, technology, logistics, and government, complemented by a community-led content and events motion. Customers include The Greenery, Monta, Vroon, Fokker, Esdec, Hillebrand Gori, HeadFirst, IV Groep, Huisman Equipment, Kubo, AgroCare, and HarvestHouse. The company operates without disclosed institutional investment and is governed under Dutch and European privacy and security standards.
Hunt & Hackett firmographics
Firmographics- Name
- Hunt & Hackett
- Legal name
- Hunt & Hackett
- Website
- https://huntandhackett.com
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Hunt & Hackett is a privately held Dutch cybersecurity firm that delivers threat-driven Managed Detection and Response, Incident Response, Threat Hunting, and security assessments to European enterprises and governments, built on Google Cloud SecOps and a proprietary cloud-native IR lab.
- Ownership category
- akta.pro rank
Hunt & Hackett industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Security Systems Services (56162)
- akta.pro primary industry
- Managed Detection & Response (MDR) (BPAEADAA)
- akta.pro secondary industries
- Incident Response, Breach Containment & Recovery (BPAKAHAB), Threat Intelligence Services (BPAEADAC), Cloud Security Logging, SIEM/SOAR & Threat Detection (HDABAHAL), Vulnerability Intelligence & Exploit Prediction (HDADAHAI)
Keywords
Where Hunt & Hackett is headquartered
LocationHeadquarters
- HQ city
- The Hague
- HQ country
- Netherlands
- HQ region
- Europe
Offices1 record
Markets served
Hunt & Hackett business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Managed Detection & Response (MDR): Recurring subscription-based MDR service providing 24/7 threat monitoring, detection, investigation, and response. Powered by Google Cloud SecOps platform. Includes continuous monitoring, threat hunting, and incident response capabilities.
- Incident Response Retainer (IRR): Pre-paid retainer service ensuring 24/7 incident response availability. Clients have dedicated IR lab instances available 24/7 for immediate upload of investigation material when security incidents occur.
- Breach & Attack Simulation (BAS): Security assessment service simulating attack scenarios to validate defense effectiveness. One-time or periodic assessment engagements.
- Security Program Gap Assessment (SPGA): Assessment service evaluating organization's current security posture against threat landscape. Identifies gaps and develops roadmap for improved cybersecurity maturity.
- Threat Hunting (TH): Proactive threat hunting service searching for evidence of existing compromise within customer environments. Utilizes frontline intelligence from APT defense operations.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Custom enterprise pricing based on organization requirements |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels9 records
Hunt & Hackett product offering
Product offeringCore offering
Hunt & Hackett delivers threat-driven cybersecurity services to European enterprises and governments, centered on Managed Detection & Response (MDR) powered by Google Cloud Security Operations. The portfolio is completed by Incident Response Retainer, Breach & Attack Simulation, Threat Hunting, Incident Response, and Security Program Gap Assessment services, combined with sector- and actor-specific threat intelligence.
Product overview
Hunt & Hackett offers a cybersecurity services portfolio centered on a unified threat-driven strategy. The core offering consists of Managed Detection & Response (MDR) powered by Google Cloud Security Operations, complemented by Incident Response Retainer (IRR), Breach & Attack Simulation (BAS), Threat Hunting (TH), Incident Response (IR), and Security Program Gap Assessment (SPGA) services. The intelligence layer includes sector-based threat landscape analysis (covering Agriculture, Energy, Maritime, Manufacturing, Technology, Logistics, and Governments), country threat profiles (Russia, China, Iran, North Korea, US, Israel), and detailed threat actor profiles tracking over 400 APT groups including APT28/Fancy Bear, APT29/Cozy Bear, APT34/OilRig, and others. Additional offerings include CyberConnect roundtables and a Members Portal providing exclusive research access. The company was founded in 2020 by former Fox-IT executives Ronald Prins and Jurjen Harskamp and is headquartered in The Hague, Netherlands.
Differentiator
Problem solved
Functional benefit
Products and services
- Managed Detection & Response (MDR) Cloud-native managed detection and response service providing 24/7 threat monitoring, detection, investigation, and response. Powered by Google Cloud Security Operations integrating SIEM, SOAR, VirusTotal, and Mandiant threat intelligence, with petabyte-scale telemetry ingestion and predictable pricing based on users rather than data volume.
- Incident Response Retainer (IRR) Pre-paid retainer service providing dedicated 24/7 access to the CERT team and a dedicated lab instance for retainer clients. Ensures immediate availability of incident response capabilities when security incidents occur, including priority data acquisition, processing, and analysis.
- Incident Response (IR) Technical analysis, triage, and response to active security incidents, backed by a cloud-based IR lab built with Infrastructure-as-Code for scalable data acquisition, processing, and analysis using DevOps principles and open-source tools such as Dissect, Velociraptor, and Timesketch.
- Threat Hunting (TH) Proactive service searching for evidence of existing compromise within customer environments. Leverages frontline intelligence from defending European organizations against APT groups, using Velociraptor Query Language and custom detection rules aligned to each client's threat landscape.
- Breach & Attack Simulation (BAS) Security assessment service that simulates attack scenarios to validate and improve organizational defenses. Tests detection and response capabilities against realistic adversary tactics, techniques, and procedures.
- Security Program Gap Assessment (SPGA) Assessment service that evaluates an organization's current security posture against its actual threat landscape. Identifies gaps and develops a roadmap for improved cybersecurity maturity and resilience.
Quantifiable outcome
- 86% of incident response cases hindered by incomplete logging and monitoring (indicating detection gap opportunity)
- +3 more outcomes
Companies that use Hunt & Hackett
Customer profileNamed customers13 records
Segments7 records
Ideal customer profiles2 records
Hunt & Hackett technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability5 records
Feature6 records
Hunt & Hackett partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and minor.
- Google CloudcoreHunt & Hackett is the first service provider in the Netherlands leveraging Google Cloud Security products. Through its MDR services, Hunt & Hackett integrates the Google Security Operations (SecOps) platform combining SIEM, SOAR, and threat intelligence. Integration includes VirusTotal and Google Cloud Threat Intelligence for enhanced detection and investigation capabilities.
- XebiaminorGoogle Cloud Partner All-Star awardee. Joint webinar on cloud security with Hunt & Hackett focusing on enhancing resilience during cloud infrastructure transition. Xebia provides cloud modernization expertise while Hunt & Hackett contributes security perspective.
- Cocoon Risk ManagementminorJoint event on hybrid threats targeting oil, gas, and offshore sectors. Cocoon Risk Management covers physical access leading to digital compromise; Hunt & Hackett demonstrates how digital attacks escalate to operational and physical impact. Combined perspective on hybrid threat landscape.
Scale indicators8 records
Recent moves6 records
Expansion highlights6 records
Hunt & Hackett competitors and assessment
Company assessmentBroad incumbents
- CrowdStrike Services: Global MDR, incident response, and threat intelligence provider built around the CrowdStrike Falcon platform. Directly comparable recurring MDR retainer and IR service model, though at materially larger scale.
- Mandiant (Google Cloud): Global leader in incident response, threat intelligence, and managed defense, now part of Google Cloud and integrated into Google SecOps. Direct overlap with Hunt & Hackett's IR and threat intelligence services, and also a strategic upstream partner.
- Orange Cyberdefense: European MSSP owned by Orange, providing managed detection, incident response, and threat intelligence across multiple European countries. Comparable enterprise go-to-market and recurring MDR/IRR services at larger scale.
- Unit 42 (Palo Alto Networks): Threat intelligence and incident response arm of Palo Alto Networks; comparable IR retainer, threat hunting, and threat-led advisory services delivered to enterprise customers globally.
Regional players
- WithSecure: Nordic-headquartered cybersecurity vendor offering MDR, incident response, and threat intelligence with strong European enterprise coverage. Comparable service portfolio and threat-driven advisory positioning.
Emerging players
- Group-IB: Global threat intelligence and incident response provider with deep APT tracking, ransomware actor monitoring, and DFIR capabilities; comparable in intelligence-led positioning and incident response retainer services.
- Recorded Future (Mastercard): Threat intelligence platform that also offers finished intelligence and IR-grade adversary tracking. Overlaps with Hunt & Hackett's APT and ransomware actor monitoring, sector profiles, and country threat assessments.
Direct peers
- Northwave: Dutch managed security services provider offering MDR, incident response, security awareness, and CERT-style services to mid-market and enterprise customers across the Benelux region; directly comparable in scale, geography, and threat-led positioning.
- Tesorion: Dutch cybersecurity firm with SOC/MDR, incident response, and threat intelligence offerings serving European enterprises. Comparable in size, Dutch origin, and threat-driven service portfolio.
- Fox-IT (NCC Group): Dutch cybersecurity services firm, founded by Hunt & Hackett's co-founders, now part of NCC Group. Delivers threat intelligence, incident response, and managed security services to European governments and enterprises, and is the direct predecessor in lineage, talent, and market.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Hunt & Hackett social profiles
Digital presenceHunt & Hackett compliance and trust
Trust signalCompliance1 record
Hunt & Hackett financial estimates
Financial estimateRevenue estimate
Valuation estimate
Hunt & Hackett leadership team
Management profileNumber of profiles
Profiles9 records
Hunt & Hackett funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Hunt & Hackett M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Hunt & Hackett
What does Hunt & Hackett do?
Hunt & Hackett delivers threat-driven cybersecurity services to European enterprises and governments, centered on Managed Detection & Response (MDR) powered by Google Cloud Security Operations. The portfolio is completed by Incident Response Retainer, Breach & Attack Simulation, Threat Hunting, Incident Response, and Security Program Gap Assessment services, combined with sector- and actor-specific threat intelligence.
Is Hunt & Hackett a public or private company?
Hunt & Hackett is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Hunt & Hackett founded?
Hunt & Hackett was founded in 2020. It employs 51 to 100 people.
Where is Hunt & Hackett based?
Hunt & Hackett is headquartered in The Hague, Netherlands, in the Europe region.
How does Hunt & Hackett make money?
Five revenue lines are on record. Managed Detection & Response (MDR) is the primary driver. The others are incident Response Retainer (IRR), breach & Attack Simulation (BAS), security Program Gap Assessment (SPGA) and threat Hunting (TH).
Who are Hunt & Hackett's main competitors?
Broad incumbents on record are CrowdStrike Services, Mandiant (Google Cloud), Orange Cyberdefense and Unit 42 (Palo Alto Networks). WithSecure is listed as a regional player. Emerging players are Group-IB and Recorded Future (Mastercard). Direct peers are Northwave, Tesorion and Fox-IT (NCC Group).
Does Hunt & Hackett have an API?
No public API is recorded for Hunt & Hackett.
What industry is Hunt & Hackett in?
Hunt & Hackett's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEADAA, Managed Detection & Response (MDR), with a secondary code of BPAKAHAB, Incident Response, Breach Containment & Recovery. Its NAICS code is 56162.