Security for the rest of us.

Detection, investigation, and incident response for the businesses that need it most. Run by people who kick out attackers for a living.

Most cyber attacks don't look like an attack until it's too late.

By the time a breach gets loud, you are watching the last step. Files encrypted, your data for sale on the darkweb, a payment made to an untraceable account nobody recognises. Everything that led there happened quietly, usually in three phases.

  1. 01The attacker gets in

    Typically without breaking anything. A weak password, a convincing email, or an unpatched server.

  2. 02The attacker looks around

    Mapping the network, finding who holds admin rights, locating the data worth taking. More often than not with the same tools your IT staff use every day.

  3. 03The attacker acts

    Files encrypted, data exfiltrated, payments redirected. For most businesses this is the first part anyone notices.

The timeline varies wildly: an afternoon, a few weeks, half a year. It depends on who is attacking and what is already in place to slow them down.

“But we have antivirus.”

Antivirus proves itself effective when the attacker brings malware. That was once the norm. Today, attackers often use legitimate software for their own purposes. They sign in with a stolen password, use a remote-access tool your team already trusts, or abuse software that is installed by default on Windows. None of that looks like a virus.

That is the gap Duntze Security fills. We use modern Endpoint Detection and Response (EDR) solutions to spot the attacker while they are still moving through your environment, not after they have encrypted your files.

Managed Detection and Response (MDR).

The ongoing service. We watch around the clock and catch intrusions while they are still small enough to be a nuisance.

I

Detect

We watch your endpoints, the accounts people log in with, and the cloud services you depend on. What gives an intruder away is behaviour. Our analysts have spent years investigating real attacks and know what that behaviour looks like in practice.

Behaviour-based detection across endpoints, identity and cloud. Monitored 24/7/365, with Threat Hunting running alongside the alerting. When something looks wrong, it already sits in front of a senior analyst who can take appropriate response measures right away. No first-tier queue to work through. No handoff between teams before someone with the experience gets to investigate the activity.

II

Investigate

As soon as we receive an alert about suspicious activity, an analyst investigates around the detection, gathering the necessary context, and determines whether it is harmless or an attacker getting in. You don't have to sort through alerts or decide what matters. We make that call for you.

Every detection is investigated with the full context around it. Critical and high-severity alerts inside 30 minutes, day and night. When a case requires deeper analysis our GIAC certified digital forensics analysts take it, down to memory, persistence, process history and more.

III

Respond

If an attacker got in, we cut their access, clear out what they left behind and work to get your systems back to normal. We handle the technical response and tell you, what happened and what we did about it.

Affected machines can be isolated from the network within minutes, stopping the attacker from using them while we investigate. Once your systems are back to normal, you get a full report covering what happened, what we did, and what needs to change so the same way in cannot be used again.

Tooling and coverage. We work with industry leaders like CrowdStrike. If you already run a platform that gives us the telemetry we need, we will look at how it fits. Coverage can reach endpoints, identity and cloud, depending on what you run and where you want us. We agree the scope with you before anything is deployed, so the service fits your environment from day one.

Response times we stand behind

SeverityAcknowledged withinCoverage
Critical / High≤ 30 minutes24/7/365
Medium≤ 4 hours24/7/365
Low / Informational≤ 1 business dayBusiness hours

These are acknowledgement times: how long before an analyst has the alert open and is working it.

We also offer a lighter business-hours tier, priced for smaller environments. Critical and high-severity alerts are still handled within 4 hours. Ask us what fits.

Digital Forensics and Incident Response (DFIR).

Ransomware, an account that was taken over, or a business email compromise. Whatever set it off, you need the same three answers: how did the attacker get in, what did they reach, and whether they are still inside. We answer these questions based on the evidence left behind. You do not have to be a monitoring client to call us.

01Stop the bleeding

Cut the attacker's access, isolate the machines involved, and keep as much of the business running as we safely can.

02Finding patient zero

We identify how the attacker got in and what evidence proves it. Cleaning up without closing the original entry point only leaves the door open for them to come back.

03Establish what was reached

Determine which systems, accounts, and data were accessed or affected. We use the available evidence to establish the scope of the incident and distinguish confirmed activity from assumptions, giving you a clear basis for the decisions that follow.

04Hand you something you can use

We document the incident, the evidence supporting our findings, the actions taken, and the recommendations for preventing a recurrence. The result is a clear, structured report that gives technical teams what they need to act and decision-makers what they need to understand.

In the middle of one right now? Email us! We'd rather hear from you early and find nothing than late and find everything.

Get help now

Our Approach: Every case is handled by a human.

Plenty of large managed security providers now route security events through a large language model, hoping it can sort the real threats from the noise. They call it an “Agentic SOC”. We've watched that approach quietly fail.

At Duntze Security we automate the parts worth automating: enrichment, evidence collection, containment actions. Judgement always stays with an analyst. Every case is triaged, investigated and closed by someone who is accountable for the call.

Why companies rely on us.

01Expertise you'd normally have to fly in.

We hold the GIAC GCFA and GSOC certifications, with a professional background in digital forensics, detection engineering, and security operations. Our experience spans private banks and critical infrastructure in Europe, as well as airlines and healthcare providers across Latin America.

02We're a small team of experienced practitioners.

The people monitoring your environment are the same people who investigate and respond when something happens. You work directly with experienced practitioners who know your environment and understand the context behind the activity they are seeing.

03Priced for the businesses we serve.

You get the same experienced practitioners and the same standard of work, without enterprise pricing or unnecessary minimums. Our services are scoped to your environment, with clear pricing and no surprises on the invoice.

04Regional context, international standard.

Our experience spans incident response across Europe and Latin America. We understand the regional context in which your business operates, while bringing the investigative methods and standards we have developed working on incidents internationally.

Tell us what you're protecting.

A short introductory call is typically enough to assess your needs and whether we are the right fit.