Onyx Cybersecurity
Onyx Cybersecurity is a Dutch cybersecurity consultancy founded in 2016 in Amersfoort, serving mid-size to large Dutch organizations (50-3,000 employees) across financial services, healthcare, technology, and the public sector with penetration testing, managed SOC services, CISO-as-a-Service, and ISO/NEN and privacy compliance advisory.
- Company typePrivate
- Founded2016
- HeadquartersAmersfoort, Netherlands
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Onyx Cybersecurity does
Onyx Cybersecurity is a Dutch cybersecurity consultancy founded in 2016 and headquartered in Amersfoort, Netherlands. The company delivers an integrated cybersecurity portfolio organized around three pillars — Mens (People), Organisatie (Organisation), and Techniek (Technology) — covering penetration testing, software security, monitoring/detection/response (MDR), security awareness and behavior programs, cyber crisis exercises, ISO/NEN implementation, and privacy (AVG/GDPR) compliance. The service is delivered through approximately twenty consultants and ethical hackers, certified under CCV Pentest Keurmerk, ISO 27001, and ISO 9001, with individual credentials spanning OSCP, OSWE, CISSP, CISM, CISA, and Lead Auditor ISO 27001. Its target customers are mid-size to large Dutch organizations (50-3,000 employees) across financial services, healthcare, technology, and the public sector, including named accounts such as Greenwheels, De Klerk, NTR, Compano, and Schouten.
The underlying technology stack is anchored on third-party platforms: Microsoft Sentinel serves as the SIEM backbone for SOC-as-a-Service, while Darktrace provides autonomous anomaly detection, with Onyx layering custom dashboards, 24/7 triage, and incident response on top. Penetration testing is delivered under the CCV Pentest Keurmerk framework with black-box, grey-box, and white-box methodologies, and is integrated into client DevSecOps pipelines for continuous testing. Generative AI is applied in pentest workflows for reconnaissance, exploitation proposal generation, and evidence documentation, while partner AI features power anomaly detection and alert enrichment within the SOC. Healthcare and e-government extensions use MedMij and DigiD assessment frameworks.
Onyx operates as a founder-led, sales-led private company with no disclosed institutional funding, serving clients exclusively in the Netherlands through direct consultative sales, free 30-minute advisory consultations, and tiered managed-service subscriptions (Start Secure, Smart Secure, Full Secure). Revenue is generated through a mix of recurring managed cybersecurity bundles (CISO-as-a-Service, SOC-as-a-Service, Privacy-as-a-Service), project-based pentesting and ISO/NEN advisory, and training/awareness professional services. Pricing is quote-based and not publicly disclosed.
Onyx Cybersecurity firmographics
Firmographics- Name
- Onyx Cybersecurity
- Legal name
- Onyx Cybersecurity
- Website
- https://onyx-cybersecurity.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Onyx Cybersecurity is a Dutch cybersecurity consultancy founded in 2016 in Amersfoort, serving mid-size to large Dutch organizations (50-3,000 employees) across financial services, healthcare, technology, and the public sector with penetration testing, managed SOC services, CISO-as-a-Service, and ISO/NEN and privacy compliance advisory.
- Ownership category
- akta.pro rank
Onyx Cybersecurity industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Cybersecurity Architecture & Security Integration (BPAEAAAL)
- akta.pro secondary industries
- Cybersecurity Operations Outsourcing (SOC / SecOps) (BPAEAMAG), Application Security & Secure Software (DevSecOps) (EDAOAIAK), Cybersecurity Learning Platforms (EDAFANAF)
Keywords
Where Onyx Cybersecurity is headquartered
LocationHeadquarters
- HQ city
- Amersfoort
- HQ country
- Netherlands
- HQ region
- Europe
Offices1 record
Markets served
Onyx Cybersecurity business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Managed Cybersecurity Services: Recurring subscription-based services including CISO-as-a-Service, Privacy-as-a-Service, and SOC-as-a-Service. These provide continuous security support with flexible team composition scaling with client needs.
- Penetration Testing and Security Assessments: One-time and recurring project-based security testing services including web application pentests, infrastructure pentests, red teaming, vulnerability assessments, and continuous pentesting engagements.
- Training and Awareness Services: Security awareness training, CISO coaching, secure code training, and NEN 7510 training delivered as classroom workshops or e-learning packages.
- Privacy and Compliance Consulting: GDPR/AVG compliance services including DPIA assessments, gap analyses, privacy officer services, and ongoing privacy consultancy.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Start Secure (Basis) - Entry-level monitoring with basic Microsoft Sentinel dashboard and monthly checks |
| Subscription | Monthly | Smart Secure (Compleet) - Full monitoring via Sentinel or Darktrace with weekly reporting and incident support |
| Subscription | Monthly | Full Secure (Extra) - 24/7 monitoring with proactive hunting and full incident response team |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels4 records
Onyx Cybersecurity product offering
Product offeringCore offering
Onyx Cybersecurity is a Dutch cybersecurity consultancy that provides managed cybersecurity services, penetration testing, security awareness training, privacy/GDPR compliance, and ISO/NEN 7510 implementation for Dutch organizations. Services are organised across three pillars — People, Organisation, and Technology — and delivered both as standalone projects (pentests, audits, training) and as recurring managed-service bundles (CISO-as-a-Service, Privacy-as-a-Service, SOC-as-a-Service with tiered Start/Smart/Full Secure packages). The company employs certified ethical hackers, security consultants, and behavior specialists to deliver prevention, detection, and response capabilities.
Product overview
Onyx Cybersecurity is a Dutch cybersecurity consultancy offering a broad managed cybersecurity portfolio organised under three pillars — Mens (People), Organisatie (Organisation), and Techniek (Technology) — delivered both as individual services and bundled as managed service packages. The core offerings include penetration testing (infrastructure, web applications, Red Team), software security, continuous monitoring and response (MDR via Microsoft Sentinel and Darktrace), security awareness and behavioral programs, cyber crisis exercises, and organisational services (ISO/NEN implementation, privacy compliance, policy development). Managed Cybersecurity packages combine CISO-as-a-Service, Privacy-as-a-Service, and SOC-as-a-Service as subscription tiers. The Onyx Cyber Toolkit organises these services for Organisation (ISO 27001, NEN 7510, Privacy), People (Awareness, CISO Coaching, Phishing, Mystery Guest), and Technology (Pentesting, Incident Response, Software Security, Crisis Management). The company is ISO 27001 certified, operates under the CCV Pentest Keurmerk, and employs certified ethical hackers and security consultants.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetratietesten (Penetration Testing) High-end ethical hacking services testing digital environments, web applications, infrastructure, and Red Team simulations, delivered under the CCV Pentest Keurmerk framework with Blackbox, Greybox, and Whitebox methodologies, including continuous pentesting integration with DevSecOps pipelines. For Dutch organisations needing demonstrable security testing.
- Software Security Application and code security testing including (web) application pentesting, MedMij-assessment, DigiD-assessment, and secure code training. Ethical hackers with software engineering backgrounds analyse code for security risks. For software development teams and SaaS providers.
- Monitoring, Detectie & Response (MDR) Managed Detection and Response service providing continuous monitoring via Microsoft Sentinel or Darktrace, expert triage and analysis, and direct incident response. Offered in tiered packages (Start Secure, Smart Secure, Full Secure) with 24/7 SOC capabilities. For organisations needing always-on security monitoring.
- Trainingen (Training Services) Security awareness training, secure code training, NEN 7510 training, IT infra team training, and CISO coaching delivered as classroom workshops, e-learning partnerships, and an online escape room for experiential learning. For organisations building internal security competency.
- Awareness & Gedrag (Security Awareness & Behavior) Behavioral security program combining listening, selection, concretization, prioritization, and change management to make safe behavior the norm. Includes phishing simulations, mystery guest tests, and an online escape room. For organisations seeking to reduce human-factor security risk.
- Crisisoefening (Cyber Crisis Exercises) Cyber crisis simulation exercises using the BOBOC methodology (Beeldvorming, Oordeelsvorming, Besluitvorming, Opdrachtverlening, Communicatie). Offered as tabletop (Basis) or integral full-day exercises (Uitgebreid), guided by experienced crisis specialists. For organisations preparing leadership and response teams for cyber incidents.
- Beleid Informatiebeveiliging (Information Security Policy) Information security policy development including baseline measurements, gap analyses, risk analyses, and ISMS implementation. Supports ISO 27001, NEN 7510, and IEC62304 norm frameworks. For organisations formalising their security governance.
- ISO, NEN en BIO Implementation ISO 27001 and NEN 7510 certification support including implementation, internal audits, and ISO 27001/NEN 7510 'light' versions for organisations not yet ready for full certification. Also covers BIO (Baseline Informatiebeveiliging Overheid) for Dutch government entities. For organisations pursuing or maintaining certification.
- Privacy (AVG/GDPR Compliance) AVG/GDPR compliance services including GAP analysis, DPIA execution, data processing registers, and Privacy-as-a-Service providing shared privacy officer support. For organisations handling personal data of EU residents.
- Managed Cybersecurity (CISO-as-a-Service, Privacy-as-a-Service, SOC-as-a-Service) Managed cybersecurity bundles providing flexible external security teams at strategic, tactical, and operational levels. CISO-as-a-Service offers strategic security leadership; Privacy-as-a-Service covers DPO and GDPR obligations; SOC-as-a-Service delivers 24/7 monitoring, detection, and response. For mid-size Dutch organisations lacking in-house security leadership.
Quantifiable outcome
- Organizations become demonstrably more cyber resilient through comprehensive approach combining technical testing, organizational measures, and human behavior change
Companies that use Onyx Cybersecurity
Customer profileNamed customers9 records
Segments4 records
Ideal customer profiles3 records
Onyx Cybersecurity technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability8 records
Feature4 records
Onyx Cybersecurity partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and minor.
- DarktracecoreCertified Darktrace partner providing monitoring, detection and response services. Onyx implements Darktrace for clients and handles full triage, providing automated threat response capabilities combined with human expertise.
- Microsoft SentinelcoreIntegration partner using Microsoft Sentinel as the SIEM platform for SOC services. Offers traditional SIEM functionality enhanced with AI, with Onyx providing custom dashboards and 24/7 monitoring.
- Cyber BustersminorCollaboration partner in crisis exercises, bringing additional expertise to cyber crisis management training and simulations.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
Onyx Cybersecurity competitors and assessment
Company assessmentBroad incumbents
- Orange Cyberdefense (Netherlands): European cybersecurity services incumbent with Dutch operations offering SOC, pentesting, and consulting — competes with Onyx for mid-market and enterprise Dutch accounts with deeper resources.
- Wortell: Large Dutch Microsoft-focused MSP that bundles security services with managed infrastructure, competing with Onyx's Microsoft Sentinel-based SOC and broader managed cybersecurity bundles.
- Fox-IT (NCC Group): Heritage Dutch cybersecurity firm now operating inside global cyber consultancy NCC Group, offering threat intelligence, MDR, and pentesting — a broader, well-capitalized incumbent competing for the same Dutch clients.
- KPN Security (incl. Cyberspecials): Dutch telecom incumbent operating a large managed security services business across SOC, incident response, and compliance — a much larger competitor with national reach.
Emerging players
- Hadrian: Amsterdam-based cybersecurity startup combining offensive testing with automated attack surface management; an emerging local peer that competes for the same Dutch technical security budgets.
Direct peers
- Hunt & Hackett: Dutch boutique cybersecurity company providing offensive security (pentesting, red teaming) and managed detection services, directly competing with Onyx's Techniek pillar and much of its managed cybersecurity offering.
- Secura (now part of Eurofins Cyber Security): Dutch-rooted cybersecurity firm delivering pentesting, red teaming, ISO 27001, and managed security services, comparable to Onyx in scope and target segment.
- Computest Security: Dutch security specialist providing penetration testing, red teaming, and security monitoring, directly overlapping with Onyx's pentest and MDR offerings in the Netherlands.
- Northwave: Dutch cybersecurity services firm offering managed detection and response, pentesting, ISO 27001, privacy, and security awareness — a near-direct overlap with Onyx's three-pillar portfolio in the same Dutch mid-market.
Regional players
- Tesorion: Dutch-origin managed security services provider delivering SOC, incident response, and threat intelligence to mid-market and enterprise clients, overlapping materially with Onyx's MDR pillar.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
Onyx Cybersecurity social profiles
Digital presenceOnyx Cybersecurity compliance and trust
Trust signalCompliance3 records
Onyx Cybersecurity financial estimates
Financial estimateRevenue estimate
Valuation estimate
Onyx Cybersecurity leadership team
Management profileNumber of profiles
Profiles1 record
Onyx Cybersecurity funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Onyx Cybersecurity M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Onyx Cybersecurity
What does Onyx Cybersecurity do?
Onyx Cybersecurity is a Dutch cybersecurity consultancy that provides managed cybersecurity services, penetration testing, security awareness training, privacy/GDPR compliance, and ISO/NEN 7510 implementation for Dutch organizations. Services are organised across three pillars — People, Organisation, and Technology — and delivered both as standalone projects (pentests, audits, training) and as recurring managed-service bundles (CISO-as-a-Service, Privacy-as-a-Service, SOC-as-a-Service with tiered Start/Smart/Full Secure packages). The company employs certified ethical hackers, security consultants, and behavior specialists to deliver prevention, detection, and response capabilities.
Is Onyx Cybersecurity a public or private company?
Onyx Cybersecurity is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Onyx Cybersecurity founded?
Onyx Cybersecurity was founded in 2016. It employs 11 to 50 people.
Where is Onyx Cybersecurity based?
Onyx Cybersecurity is headquartered in Amersfoort, Netherlands, in the Europe region.
How does Onyx Cybersecurity make money?
Four revenue lines are on record. Managed Cybersecurity Services are the primary driver. The others are penetration Testing and Security Assessments, training and Awareness Services and privacy and Compliance Consulting.
Who are Onyx Cybersecurity's main competitors?
Broad incumbents on record are Orange Cyberdefense (Netherlands), Wortell, Fox-IT (NCC Group) and KPN Security (incl. Cyberspecials). Hadrian is listed as an emerging player. Direct peers are Hunt & Hackett, Secura (now part of Eurofins Cyber Security), Computest Security and Northwave. Tesorion is listed as a regional player.
Does Onyx Cybersecurity have an API?
No public API is recorded for Onyx Cybersecurity.
What industry is Onyx Cybersecurity in?
Onyx Cybersecurity's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEAAAL, Cybersecurity Architecture & Security Integration, with a secondary code of BPAEAMAG, Cybersecurity Operations Outsourcing (SOC / SecOps). Its NAICS code is 5415 and its SIC code is 7370.