Professional, spot-on, and personal. Their consultants give the concise answers we need and proactively bring in valid points to strengthen our monitoring and setup on Managed Sentinel and Microsoft MDR.
Built by the people who do the work.
Falconer Security is a Microsoft-native security operations team based in Sweden, run by senior practitioners who came from bank-grade detection engineering and offensive security - and who still do the work themselves.
The mid-market had two options. Both were bad.
We spent years inside the kind of security operation almost no mid-sized company can afford: detection engineering and incident response at a major Nordic financial institution, and offensive security work that taught us how attackers actually move through Microsoft environments.
From there, the gap was hard to ignore. The organisations that most needed that level of care - regulated, growing, running everything on Microsoft 365 and Azure - could not get it. What the market offered them was a choice between nothing and a ticket queue.
Most 50-500 person organisations cannot justify a security team, so the tenant runs on defaults and hope. It works until the day it very much does not.
A generic MSSP puts Tier-1 analysts on a dashboard, forwards what fires, and calls it detection and response. The alerts move; the investigation never happens.
A small firm where the people who wrote detections inside a major Nordic bank and broke into systems for a living investigate every incident themselves - on the Microsoft licenses you already own.
Commitments, not adjectives
The ethos that runs through every service page, stated as things you can hold us to.
Senior-led, no tiers
A senior practitioner investigates every incident and runs every engagement. There is no Tier-1 queue to survive first.
No black box
We work inside your tenant, in your tools. You can watch every query we run and read every action we take, live.
Deep, not broad
Microsoft only: Sentinel, Defender, Entra, Azure. We would rather master your stack than gesture at forty tools we barely operate.
EU-sovereign
Founded in Sweden, operated from the EU. Your data stays in your tenant, handled under GDPR, built for NIS2.
A clean exit, by design
Your licenses, your configurations, your detections - all yours if you leave. We earn renewals; we do not engineer lock-in.
We tell you what you don’t need
No gateway you don’t need, no Defender plan that doesn’t earn its cost, no assessment before it is worth your money. Ask the sales call.
The opposite of the box-ticking MSSP
The industry’s open secret is that much of “managed detection and response” is junior analysts forwarding alerts. We built Falconer to be the opposite of that - and being small is exactly what makes it possible.
- Tier-1 analysts who monitor dashboards and forward alerts
- Hundreds of supported tools, none operated deeply
- A ticket number and an SLA between you and whoever is on shift
- "Detection and response" that is mostly detection, barely response
- A senior practitioner investigates every incident - there is no Tier 1
- One stack, mastered: Sentinel, Defender, Entra, Azure
- The same senior people, every time, with a direct line
- Investigation and containment, not alert forwarding
We are deliberately small. That is not a limitation we apologise for; it is the delivery model.
Your data, your control
A security provider is itself a third party with access. Here is how we keep that risk boring.
Your data stays in your tenant
Logs, alerts, and incident records live in your Sentinel workspace and Microsoft estate. Nothing is copied to a Falconer platform, because there isn’t one.
Access you can see and revoke
We work through scoped, delegated access you grant. Every action we take lands in your audit log, and you can cut access yourself, today.
Your licenses, your configurations
Everything we build - detections, automations, policies - is built in your tenant, on your licenses. It is yours on day one and yours if you leave.
EU residency, by design
A Swedish company, EU operations, GDPR-governed handling, NIS2-aligned processes. Jurisdiction is never a surprise.
Don’t take our word for it
Patrick Sandu, Founder & COO, holds OSCP and OSWE and is Microsoft-certified. View his LinkedIn.
We work with 50-500 person organisations across the EU and Nordics - many of them regulated, all of them on Microsoft. We are growing deliberately: senior people only, one client at a time, investing in the craft rather than the headcount. If that pace sounds slow, it is also why the person on your incident is never a stranger.