NFIR B.V.
NFIR B.V. is a Netherlands-based cybersecurity firm offering managed detection and response, incident response, digital forensics, penetration testing, and security awareness services to Dutch government, education, healthcare, and corporate clients.
- Company typePrivate
- Founded2016
- HeadquartersThe Hague, Netherlands
- Headcount11–50
- GTM typeB2B
- OfferingServices
What NFIR B.V. does
NFIR B.V. (Nederlands Forensisch Incident Response) is a Dutch private cybersecurity firm founded in 2016, headquartered in Rijswijk with a second operational office in Zwolle housing its 24/7 SOC. The company delivers a tightly integrated portfolio spanning reactive, detective, and preventive services: Incident Response (on-demand and a 3-hour-response retainer), Digital Forensic Investigation, Managed Detection & Response (MDR Essentials and MDR Advanced tiers), penetration testing across infrastructure, web/API/mobile/OT/AI systems, Security Awareness training, Social Engineering simulation, NIS2 consultancy, and CIS Controls-based security consultancy.
The underlying technology stack is anchored by a proprietary SIEM-SOC platform that aggregates 100+ international threat feeds plus NCSC intelligence, integrates AI-driven detection with UEBA, and supports SOAR-based automated response. All MDR data is processed and retained for one year within the Netherlands, a deliberate positioning for Dutch sovereignty-sensitive buyers. Forensic work is conducted under a Dutch Ministry of Justice POB license (#1672) using internationally approved methodologies that produce legally admissible reports, and the team carries advanced ethical-hacking certifications (OSCP, OSWE, OSEP, OSWP, CPTS, CBBH, eWPT).
Revenue is generated through a mix of recurring subscriptions (MDR, IR Retainer, multi-year awareness programs) and project-based professional services (pentests, IR engagements, forensic investigations, NIS2 gap analyses). The company sells exclusively through direct enterprise field sales within the Netherlands, targeting government, education, healthcare, critical infrastructure, corporate, and SMB clients; named reference customers include Ministerie van VWS (CoronaMelder pentest), Gemeente Lochem, ROC Mondriaan, and QuaWonen. NFIR is independently owned with no disclosed external funding or investor base.
NFIR B.V. firmographics
Firmographics- Name
- NFIR B.V.
- Legal name
- NFIR B.V.
- Website
- https://nfir.nl
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- NFIR B.V. is a Netherlands-based cybersecurity firm offering managed detection and response, incident response, digital forensics, penetration testing, and security awareness services to Dutch government, education, healthcare, and corporate clients.
- Ownership category
- akta.pro rank
NFIR B.V. industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Security Systems Services (56162), Computer Facilities Management Services (541513)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Managed Detection & Response (MDR) (BPAEADAA)
- akta.pro secondary industries
- Endpoint Security Managed Services (EDR/XDR) (BPAEADAH), Endpoint Forensics & Incident Response (DFIR) (HDADAEAJ), Incident Response, Forensics & Recovery for Critical Infrastructure (EUADANAI)
Keywords
Where NFIR B.V. is headquartered
LocationHeadquarters
- HQ city
- The Hague
- HQ country
- Netherlands
- HQ region
- Europe
Offices2 records
Markets served
NFIR B.V. business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Infrastructure, Marketing or Sales, Others
Revenue model
- Managed Detection & Response (MDR): Recurring monthly/annual subscription for 24/7 security monitoring and response. Offered in two tiers: MDR Essentials and MDR Advanced, with varying levels of log source coverage and response capabilities.
- Pentesting Services: Project-based penetration testing services for infrastructure, web applications, APIs, mobile applications, OT environments, and AI systems. Scope determined during intake with custom proposals.
- Incident Response Retainer: Annual retainer contract guaranteeing 24/7 access to CERT team, 3-hour response time commitment, bi-annual readiness assessments, and post-incident evaluations.
- Incident Response (On-demand): Reactive incident response services for organizations facing active cyberattacks, ransomware, or data breaches. Emergency response via 24/7 hotline.
- Digital Forensic Investigation: Investigation services for data breaches, fraud, blackmail, compromised mailboxes, and evidence seizure. Concludes with legally admissible forensic reports.
- Security Awareness Programs: 3-year awareness programs combining e-learning (Arda platform), phishing simulations, presentations, and social engineering tests. Also offered as individual components.
- Security Consultancy / CSAT Tool: CIS Controls-based security assessments and roadmaps using proprietary assessment tool, with 2-year platform access and periodic review sessions.
- Social Engineering Services: Specialized testing including mystery guest visits, voice phishing, AI deepfakes, voice cloning, smishing, and mail phishing assessments.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | MDR Essentials - Essential threat detection on identities and endpoints |
| Subscription | Annual | MDR Advanced - Complete coverage of attack surface |
| Subscription | Annual | Incident Response Retainer - Annual retainer contract |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
NFIR B.V. product offering
Product offeringCore offering
NFIR B.V. delivers managed cybersecurity and incident response services to Dutch organizations, anchored by a 24/7 Security Operations Center offering Managed Detection & Response (MDR) on a proprietary SIEM platform. Reactive services include Incident Response with a 3-hour guaranteed response time, digital forensic investigation under POB license, and on-demand breach handling, while preventive offerings include certified penetration testing (infrastructure, web, API, mobile, OT, AI), security awareness training, social engineering simulations, and NIS2/CIS Controls consultancy.
Product overview
NFIR B.V. is a Dutch cybersecurity specialist offering a portfolio of interconnected services spanning preventive, detective, and reactive cybersecurity. The core offering is built around Managed Detection & Response (MDR), with two tiers — MDR Essentials (identity/endpoint focus) and MDR Advanced (full attack surface coverage including network, cloud and backup) — running on a proprietary SIEM-SOC platform in the Netherlands with 1-year data retention. Preventive services include Pentesten (certified ethical hacking across infrastructure, web applications, APIs, mobile apps, OT and AI systems) backed by a CCV quality mark, and Security Awareness training via the ARDA e-learning platform combined with Social Engineering simulation services. Reactive services are anchored by an Incident Response retainer contract (3-hour guaranteed response) and a standalone Incident Response team using NIST/SANS methodologies, alongside Digitaal Forensisch Onderzoek (digital forensic investigation) backed by a POB license. NIS2 Consultancy and Security Consultancy (CIS Controls) round out the advisory layer. The services are designed to interconnect: MDR detects threats that pentests prevent; IR retainer ensures preparedness; forensic investigation provides post-incident answers; and awareness training strengthens the human layer across all.
Differentiator
Problem solved
Functional benefit
Products and services
- Managed Detection & Response (MDR) Continuous 24/7 SOC monitoring and threat detection/response service for organizations across IT and OT environments, with two subscription tiers (MDR Essentials and MDR Advanced) differing in log source coverage and response capabilities.
- Incident Response Reactive incident response service for organizations facing active cyberattacks, ransomware, data breaches, or network intrusions, with forensic evidence preservation and legally admissible reporting.
- Incident Response Retainer Annual pre-paid contract providing guaranteed 24/7 CERT availability and a 3-hour response commitment for organizations preparing for potential cyber incidents.
- Digital Forensic Investigation Forensic investigation service for data breaches, fraud, blackmail, BEC/CEO fraud, and evidence seizure, conducted under POB license with legally admissible reporting.
- Penetration Testing (Pentesten) Certified penetration testing of infrastructure, web applications, APIs, mobile applications, and OT environments by ethical hackers holding OSCP, OSWE, OSEP, CPTS, and eWPT credentials under the CCV quality mark.
- AI Penetration Testing Specialized penetration testing targeting AI systems and AI-integrated applications to identify vulnerabilities unique to AI deployments.
- Security Awareness Program Structured multi-year security awareness training delivered via the Arda e-learning platform, including phishing simulations, executive presentations, crisis simulations, and the Skywave serious game.
- Social Engineering Testing Simulated psychological manipulation tests including mystery guest visits, voice phishing, AI deepfake and voice cloning, smishing, and mail phishing to evaluate human-layer vulnerabilities.
- Security Consultancy (CIS Controls) Strategic cybersecurity advisory based on CIS Controls v8, using NFIR's proprietary CSAT assessment tool to deliver inventories, policy documentation, gap analysis, and prioritized roadmaps.
- NIS2 Consultancy Advisory service guiding essential and important entities toward NIS2 compliance through gap analysis, Cyberbeveiligingswet preparation, and implementation of the 10 NIS2 building blocks.
Quantifiable outcome
- 3-hour guaranteed response time for incident response retainer clients
- +3 more outcomes
Companies that use NFIR B.V.
Customer profileNamed customers7 records
Segments6 records
Ideal customer profiles5 records
NFIR B.V. technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability3 records
Feature6 records
NFIR B.V. partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and minor.
- ArdacoreNFIR partnered with Arda as the e-learning platform for security awareness programs. Arda differentiates through focus on behavioral change rather than just knowledge transfer, using realistic scenarios, professional videos, interactive modules, and gamification. The platform supports organizations in meeting NIS2, ISO27001, and AVG (GDPR) compliance requirements through ongoing learning pathways.
- CCRC (Cybersecurity & Crisis Response Center)coreNFIR and CCRC extended their collaboration to strengthen digital resilience together. CCRC focuses on crisis coordination and response for Dutch organizations, while NFIR provides technical incident response and forensic expertise. The partnership enables comprehensive coverage from crisis coordination through technical incident resolution.
- CCV (Centrum voor Criminaliteitspreventie en Veiligheid)coreCCV awards the pentest quality mark (CCV-keurmerk) that NFIR holds since January 2022. This certification is based on NEN-EN-ISO/IEC standards 17021 and 17065, providing customers assurance of professional and high-quality pentest execution.
- BPOB (Branchevereniging Particuliere Onderzoeksbureaus)minorNFIR is a member of BPOB, the trade association for private investigation bureaus. Membership requires adherence to applicable legislation and the Privacy Code of Conduct, demonstrating commitment to lawful and ethical investigation practices.
Scale indicators6 records
Recent moves6 records
Expansion highlights5 records
NFIR B.V. competitors and assessment
Company assessmentBroad incumbents
- Deloitte Netherlands - Cyber Risk: Big Four advisory practice delivering incident response, managed detection, pentesting, and NIS2 advisory to Dutch enterprises and ministries. Competes with NFIR on advisory and managed services, particularly in regulated sectors, but as one offering within a large multi-disciplinary firm.
- Orange Cyberdefense: European MSSP operating a large SOC network and delivering managed detection, incident response, and threat intelligence across multiple countries. Overlaps with NFIR on MDR/IR but at significantly greater scale, with a broader portfolio and international footprint.
- KPN Security / Cybersprint: Dutch telecom incumbent operating a broad cybersecurity portfolio including SOC/MDR, vulnerability management, and incident response. Competes with NFIR across multiple service lines, particularly with Dutch enterprise and government buyers, but as part of a wider telecom product suite rather than a pure-play specialist.
Emerging players
- Guardey: Dutch security awareness and human risk management vendor. Directly comparable to NFIR's Arda-powered awareness offering; smaller and more specialized, representing both a partner and a partial competitor in the awareness layer.
- Hadrian: Netherlands-based attack-surface management and continuous pentesting provider. Adjacent to NFIR's pentest practice with overlapping mid-market Dutch customers, but more focused on automated external testing rather than full-service IR/MDR.
Direct peers
- Hudson Cybertec: Dutch OT/ICS cybersecurity specialist offering monitoring, incident response, and pentesting for industrial environments. Comparable to NFIR's OT pentest and critical-infrastructure IR capabilities, with similar regulatory/sovereignty positioning.
- Fox-IT (NCC Group): Dutch-headquartered cybersecurity firm specializing in incident response, digital forensics, and managed security services. Direct overlap with NFIR on CERT-style IR work, SOC/MDR offerings, and Dutch public-sector clientele; broader international footprint via NCC Group.
- Eye Security: Dutch MDR and incident response provider focused on SMB and mid-market organizations, with 24/7 SOC and compliance tooling. Direct peer in the Dutch MDR market with comparable service packaging and customer segment focus.
- Northwave: Netherlands-based cybersecurity specialist delivering managed detection & response, incident response, security awareness, and compliance services. Closely comparable business model and customer base to NFIR, with similar mid-market Dutch focus.
- Secura (DNV): Benelux-rooted cybersecurity firm offering pentesting, red teaming, incident response, and managed security services. Comparable service portfolio across preventive testing and reactive IR, with broader European reach under DNV ownership.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
NFIR B.V. social profiles
Digital presenceNFIR B.V. compliance and trust
Trust signalCompliance5 records
NFIR B.V. financial estimates
Financial estimateRevenue estimate
Valuation estimate
NFIR B.V. leadership team
Management profileNumber of profiles
NFIR B.V. funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
NFIR B.V. M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about NFIR B.V.
What does NFIR B.V. do?
NFIR B.V. delivers managed cybersecurity and incident response services to Dutch organizations, anchored by a 24/7 Security Operations Center offering Managed Detection & Response (MDR) on a proprietary SIEM platform. Reactive services include Incident Response with a 3-hour guaranteed response time, digital forensic investigation under POB license, and on-demand breach handling, while preventive offerings include certified penetration testing (infrastructure, web, API, mobile, OT, AI), security awareness training, social engineering simulations, and NIS2/CIS Controls consultancy.
Is NFIR B.V. a public or private company?
NFIR B.V. is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was NFIR B.V. founded?
NFIR B.V. was founded in 2016. It employs 11 to 50 people.
Where is NFIR B.V. based?
NFIR B.V. is headquartered in The Hague, Netherlands, in the Europe region.
How does NFIR B.V. make money?
Eight revenue lines are on record. Managed Detection & Response (MDR) is the primary driver. The others are pentesting Services, incident Response Retainer, incident Response (On-demand), digital Forensic Investigation, security Awareness Programs, security Consultancy / CSAT Tool and social Engineering Services.
Who are NFIR B.V.'s main competitors?
Broad incumbents on record are Deloitte Netherlands - Cyber Risk, Orange Cyberdefense and KPN Security / Cybersprint. Emerging players are Guardey and Hadrian. Direct peers are Hudson Cybertec, Fox-IT (NCC Group), Eye Security, Northwave and Secura (DNV).
Does NFIR B.V. have an API?
No public API is recorded for NFIR B.V..
What industry is NFIR B.V. in?
NFIR B.V.'s product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEADAA, Managed Detection & Response (MDR), with a secondary code of BPAEADAH, Endpoint Security Managed Services (EDR/XDR). Its NAICS code is 56162 and its SIC code is 7373.