INCIDE
INCIDE is an independent cybersecurity firm founded in 2005, operating from Zoetermeer (Netherlands) and Barcelona (Spain), delivering AI-accelerated security advisory, pentesting, MDR, DFIR and business continuity services to over 1,000 enterprise, government and critical infrastructure clients.
- Company typePrivate
- Founded2005
- HeadquartersBarcelona, Spain
- Headcount11–50
- GTM typeB2B
- OfferingServices
What INCIDE does
INCIDE is an independent cybersecurity and digital forensics firm founded in 2005, headquartered in Zoetermeer (Netherlands) with a regional office in Barcelona (Spain). The company delivers a multi-disciplinary security services portfolio spanning Security Advisory (including CISO-as-a-Service), Penetration Testing, Managed Detection and Response (MDR), Digital Forensics and Incident Response (DFIR), and Business Continuity. Service delivery is positioned as "AI-accelerated, human-led," with the firm operating a single global delivery practice staffed by more than 100 senior security specialists and supported by integration of 40+ threat intelligence sources across more than 100,000 monitored endpoints.
The technology footprint is services-native rather than product-native: the firm wraps its own methodologies, playbooks and analyst workflows around third-party tooling, and explicitly disclaims vendor affiliations so it can recommend best-fit solutions to clients. Core platforms include a 24/7 MDR operations capability, incident response retainers, and structured advisory engagements that combine governance, risk and compliance work with technical testing. AI tooling is applied to accelerate analyst workflows (detection engineering, pentest exploitation, triage in DFIR) rather than marketed as a standalone product, and the firm has not disclosed proprietary models, research output or patents.
INCIDE's business model is services-based, generating revenue through multi-year enterprise contracts with retained advisory relationships, recurring MDR subscriptions, and project-based penetration testing and incident response engagements. The firm targets enterprise, government and critical infrastructure buyers, with a client base exceeding 1,000 organizations and named references including AFAS, Avy, CLB, FuturumShop, Municipio de Arnhem, OPP, AZ (football club) and the SURF consortium of Dutch educational and research institutions. Pricing is anchored on engagement scope, endpoint volume and seniority of practitioners deployed, with multi-year terms the dominant commercial shape. Go-to-market emphasizes deep technical specialization and bespoke engagement over commoditized product resale.
INCIDE firmographics
Firmographics- Name
- INCIDE
- Legal name
- DEFION Security B.V.
- Website
- https://incide.es
- Company type
- Private
- Founded year
- 2005
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- INCIDE is an independent cybersecurity firm founded in 2005, operating from Zoetermeer (Netherlands) and Barcelona (Spain), delivering AI-accelerated security advisory, pentesting, MDR, DFIR and business continuity services to over 1,000 enterprise, government and critical infrastructure clients.
- Ownership category
- akta.pro rank
INCIDE industry classification
Industry- Product category
- Managed Cybersecurity Services
- NAICS
- Investigation and Security Services (5616)
- SIC
- Services-Engineering, Accounting, Research, Management (8700), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Security Incident Response (IR) & Digital Forensics Services (BPAEADAI)
- akta.pro secondary industries
- Endpoint Security Managed Services (EDR/XDR) (BPAEADAH), Vulnerability Management & Penetration Testing Services (BPAEADAD), Cybersecurity & Identity Consulting (BPAHAEAG)
Keywords
Where INCIDE is headquartered
LocationHeadquarters
- HQ city
- Barcelona
- HQ country
- Spain
- HQ region
- Europe
Offices2 records
Markets served
INCIDE business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Managed Detection & Response (MDR): 24/7 SOC monitoring and threat detection services. Continuous endpoint monitoring across 100,000+ endpoints. Includes alert triage, threat investigation, and incident response capabilities.
- Security Advisory Services: CISO-as-a-Service and strategic security resilience consulting. Security posture evaluations, compliance assessments, and actionable security roadmaps for enterprise clients.
- Pentesting Services: Technical security testing including vulnerability assessments and penetration testing. AI-accelerated delivery with results in 24 hours.
- Digital Forensics & Incident Response (DFIR): 24/7 incident response and digital forensics for cyber crisis situations. Includes containment, forensic analysis, and recovery services worldwide.
- Business Continuity Services: Business continuity planning and incident preparedness services to minimize operational disruption and recovery time after security incidents.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | Enterprise Security Programs |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
INCIDE product offering
Product offeringCore offering
INCIDE provides managed cybersecurity and digital forensics services to European enterprises through a 24/7 Security Operations Center that monitors 100,000+ endpoints. The portfolio spans strategic advisory (CISO-as-a-Service), AI-accelerated penetration testing with 24-hour delivery, Managed Detection & Response, Digital Forensics & Incident Response, and business continuity planning. Services are delivered by 100+ senior analysts across Zoetermeer and Barcelona with average response times below five minutes.
Product overview
DEFION Security offers a unified managed security services portfolio covering the entire security lifecycle. The company provides five integrated core services: Security Advisory Services (strategic consulting and CISO-as-a-Service), Pentesting Services (AI-accelerated penetration testing with 24-hour delivery), Managed Detection & Response (24/7 SOC monitoring 100,000+ endpoints), Digital Forensics & Incident Response (DFIR crisis management), and Business Continuity Services (recovery planning). All services are delivered by 100+ senior analysts across two offices in Zoetermeer and Barcelona, with average response times under 5 minutes. The company uses AI to accelerate testing and detection while maintaining human expert decision-making.
Differentiator
Problem solved
Functional benefit
Products and services
- Security Advisory Services Strategic security consulting service that includes security posture evaluations, compliance assessments, and CISO-as-a-Service engagements, translating best practices and regulatory requirements into a concrete action plan. Targeted at enterprise clients needing demonstrable improvement in security maturity and resilience.
- Pentesting Services Penetration testing and technical security review service that simulates attacker methodologies to identify vulnerabilities. AI-accelerated delivery produces first vulnerability findings in 24 hours versus the industry-standard 6-week timeline. Suited to enterprises and SaaS providers needing rapid, continuous attack-readiness validation.
- Managed Detection & Response (MDR) 24/7 Managed SOC service providing adaptive threat detection across IT, OT, and IoT environments, with specialists monitoring over 100,000 endpoints. Includes alert triage, threat investigation, and incident response with sub-five-minute average response times. Designed for enterprises and large institutions requiring continuous, senior-led security operations.
- Digital Forensics & Incident Response (DFIR) 24/7 incident response and digital forensics service providing crisis management, containment, forensic analysis, and recovery. Available worldwide for organizations experiencing active cyber incidents, backed by senior analysts with 20+ years of experience.
- Business Continuity Services Business continuity planning and incident preparedness service ensuring organizations can recover operations within hours after a cyber attack. Includes continuity program design, incident preparedness exercises, and alignment with DFIR playbooks to minimize operational and financial disruption.
Quantifiable outcome
- Average incident response time: <5 minutes
- +4 more outcomes
Companies that use INCIDE
Customer profileNamed customers6 records
Segments7 records
Ideal customer profiles6 records
INCIDE technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability2 records
Feature3 records
INCIDE partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered flagship and core.
- AZflagshipMulti-year strategic partnership making DEFION the Official Security Provider for AZ (professional football club). DEFION protects the club's valuable data used for on-field and off-field performance. This partnership represents a flagship customer win demonstrating DEFION's ability to secure high-profile organizations.
- SURFcoreMDR deployment partnership covering 75+ Dutch universities, polytechnics, and vocational training institutions. DEFION and DTX provide 24/7 protection for Netherlands educational and research infrastructure. This represents a core strategic partnership protecting critical research sector across the Netherlands.
- DTXcoreJoint MDR deployment with DEFION for SURF's 75+ educational institutions in the Netherlands. DTX collaborates with DEFION to deliver managed detection and response services to the Dutch research and education sector.
Scale indicators7 records
Recent moves5 records
Expansion highlights5 records
INCIDE competitors and assessment
Company assessmentDirect peers
- Secarma: Secarma is a UK-based boutique cybersecurity consultancy specializing in penetration testing, managed detection, and incident response. Highly comparable services and customer profile to DEFION, particularly its pentesting and DFIR lines.
- Fox-IT: Fox-IT is a Dutch cybersecurity firm offering managed security, DFIR, pentesting, and threat intelligence to Benelux enterprises and governments. Operates a similar senior-analyst, 24/7 SOC model from the Netherlands, directly overlapping DEFION's Zoetermeer base and service portfolio.
- Mnemonic: Mnemonic is a Norwegian MSSP providing managed detection and response, threat intelligence, IR, and security advisory across Northern Europe. Comparable European boutique MSSP with overlapping service portfolio and similar senior-analyst-led delivery model.
- S2 Grupo: S2 Grupo is a Valencia-headquartered Spanish cybersecurity firm providing MDR/managed security, DFIR, pentesting, and CISO advisory to large Spanish enterprises and public bodies. Closest geographic and service-line peer to INCIDE's Barcelona operation.
- Wortell: Wortell is a Dutch managed security and Microsoft-focused IT services firm headquartered in the Netherlands. Competes with DEFION for Dutch enterprise and government accounts, particularly in managed detection and Microsoft-centric security operations.
- Orange Cyberdefense: Orange Cyberdefense is the European MSSP arm of Orange Business, delivering 24/7 SOC/MDR, DFIR, pentesting and threat intel across Europe. Closest scaled European peer in terms of service mix; DEFION competes for many of the same European mid-market and enterprise accounts.
Broad incumbents
- NCC Group: NCC Group is a UK-listed cybersecurity and software resilience consultancy (parent of Fox-IT) offering DFIR, managed detection, advisory and assurance globally. Broader incumbent with overlapping services to DEFION's DFIR, advisory and pentesting lines, and the European competitor to watch most closely.
- Kudelski Security: Kudelski Security is the Swiss-headquartered cybersecurity division of the Kudelski Group, offering managed security, DFIR, advisory and managed detection across Europe and the US. Larger, broader incumbent with overlapping services and shared European enterprise/government customer base.
- Cybereason: Cybereason is a global XDR and MDR provider with European operations, offering AI-driven endpoint detection, IR retainers, and managed defense. Competes with DEFION in AI-augmented MDR/XDR across European enterprise accounts.
- DNV (Cyber): DNV's Cyber business line delivers managed security, incident response, and certification services to critical infrastructure and industrial operators in Europe. Overlaps with DEFION's Critical Infrastructure and Industrial verticals, particularly on OT/ICS engagements.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks7 records
Key highlights7 records
Customer concentration
INCIDE social profiles
Digital presenceINCIDE financial estimates
Financial estimateRevenue estimate
Valuation estimate
INCIDE leadership team
Management profileNumber of profiles
INCIDE funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
INCIDE M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about INCIDE
What does INCIDE do?
INCIDE provides managed cybersecurity and digital forensics services to European enterprises through a 24/7 Security Operations Center that monitors 100,000+ endpoints. The portfolio spans strategic advisory (CISO-as-a-Service), AI-accelerated penetration testing with 24-hour delivery, Managed Detection & Response, Digital Forensics & Incident Response, and business continuity planning. Services are delivered by 100+ senior analysts across Zoetermeer and Barcelona with average response times below five minutes.
Is INCIDE a public or private company?
INCIDE is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was INCIDE founded?
INCIDE was founded in 2005. It employs 11 to 50 people.
Where is INCIDE based?
INCIDE is headquartered in Barcelona, Spain, in the Europe region.
How does INCIDE make money?
Five revenue lines are on record. Managed Detection & Response (MDR) is the primary driver. The others are security Advisory Services, pentesting Services, digital Forensics & Incident Response (DFIR) and business Continuity Services.
Who are INCIDE's main competitors?
Direct peers on record are Secarma, Fox-IT, Mnemonic, S2 Grupo, Wortell and Orange Cyberdefense. Broad incumbents are NCC Group, Kudelski Security, Cybereason and DNV (Cyber).
Does INCIDE have an API?
No public API is recorded for INCIDE.
What industry is INCIDE in?
INCIDE's product category is Managed Cybersecurity Services. Its primary akta.pro industry code is BPAEADAI, Security Incident Response (IR) & Digital Forensics Services, with a secondary code of BPAEADAH, Endpoint Security Managed Services (EDR/XDR). Its NAICS code is 5616 and its SIC code is 8700.