About Falconer

Built by the people who do the work.

Falconer Security is a Microsoft-native security operations team based in Sweden, run by senior practitioners who came from bank-grade detection engineering and offensive security - and who still do the work themselves.

Founder-led, senior on every engagement EU and Nordic operations, founded in Sweden Microsoft-native by choice, not convenience No black box: you see what we see
Falconer SecurityThe short version Due-diligence friendly
Founded
Sweden
EU operations · EU data handling
Focus
Microsoft security operations
Sentinel · Defender · Entra · Azure - deep, not broad
Background
Bank-grade detection · offensive security
Detection engineering inside a major Nordic financial institution
Model
Founder-led delivery
A senior practitioner on every engagement · no tiers
Everything on this page is checkable · nothing is inflated
Why we exist

The mid-market had two options. Both were bad.

We spent years inside the kind of security operation almost no mid-sized company can afford: detection engineering and incident response at a major Nordic financial institution, and offensive security work that taught us how attackers actually move through Microsoft environments.

From there, the gap was hard to ignore. The organisations that most needed that level of care - regulated, growing, running everything on Microsoft 365 and Azure - could not get it. What the market offered them was a choice between nothing and a ticket queue.

Option one
Do nothing

Most 50-500 person organisations cannot justify a security team, so the tenant runs on defaults and hope. It works until the day it very much does not.

Option two
The alert forwarder

A generic MSSP puts Tier-1 analysts on a dashboard, forwards what fires, and calls it detection and response. The alerts move; the investigation never happens.

What we built
The senior-operator alternative

A small firm where the people who wrote detections inside a major Nordic bank and broke into systems for a living investigate every incident themselves - on the Microsoft licenses you already own.

How we work

Commitments, not adjectives

The ethos that runs through every service page, stated as things you can hold us to.

Senior-led, no tiers

A senior practitioner investigates every incident and runs every engagement. There is no Tier-1 queue to survive first.

No black box

We work inside your tenant, in your tools. You can watch every query we run and read every action we take, live.

Deep, not broad

Microsoft only: Sentinel, Defender, Entra, Azure. We would rather master your stack than gesture at forty tools we barely operate.

EU-sovereign

Founded in Sweden, operated from the EU. Your data stays in your tenant, handled under GDPR, built for NIS2.

A clean exit, by design

Your licenses, your configurations, your detections - all yours if you leave. We earn renewals; we do not engineer lock-in.

We tell you what you don’t need

No gateway you don’t need, no Defender plan that doesn’t earn its cost, no assessment before it is worth your money. Ask the sales call.

The line we draw

The opposite of the box-ticking MSSP

The industry’s open secret is that much of “managed detection and response” is junior analysts forwarding alerts. We built Falconer to be the opposite of that - and being small is exactly what makes it possible.

The generic MSSP
  • Tier-1 analysts who monitor dashboards and forward alerts
  • Hundreds of supported tools, none operated deeply
  • A ticket number and an SLA between you and whoever is on shift
  • "Detection and response" that is mostly detection, barely response
Falconer
  • A senior practitioner investigates every incident - there is no Tier 1
  • One stack, mastered: Sentinel, Defender, Entra, Azure
  • The same senior people, every time, with a direct line
  • Investigation and containment, not alert forwarding

We are deliberately small. That is not a limitation we apologise for; it is the delivery model.

Choosing a provider is a risk decision

Your data, your control

A security provider is itself a third party with access. Here is how we keep that risk boring.

Your data stays in your tenant

Logs, alerts, and incident records live in your Sentinel workspace and Microsoft estate. Nothing is copied to a Falconer platform, because there isn’t one.

Access you can see and revoke

We work through scoped, delegated access you grant. Every action we take lands in your audit log, and you can cut access yourself, today.

Your licenses, your configurations

Everything we build - detections, automations, policies - is built in your tenant, on your licenses. It is yours on day one and yours if you leave.

EU residency, by design

A Swedish company, EU operations, GDPR-governed handling, NIS2-aligned processes. Jurisdiction is never a surprise.

Proof

Don’t take our word for it

Professional, spot-on, and personal. Their consultants give the concise answers we need and proactively bring in valid points to strengthen our monitoring and setup on Managed Sentinel and Microsoft MDR.

Coen Smiers Project Manager, Rods & Cones
Verified on GoodFirms
5.0
GoodFirms rating
OSCP · OSWE
Patrick Sandu, Founder & COO
Sweden
Registered & operated

Patrick Sandu, Founder & COO, holds OSCP and OSWE and is Microsoft-certified. View his LinkedIn.

Who we serve, and where this is going.

We work with 50-500 person organisations across the EU and Nordics - many of them regulated, all of them on Microsoft. We are growing deliberately: senior people only, one client at a time, investing in the craft rather than the headcount. If that pace sounds slow, it is also why the person on your incident is never a stranger.

Explore the services
Contact

Tell us what you’re dealing with

A Microsoft security specialist reads every message and replies, usually within one business day. Whether you need monitoring, help with a specific tool, or just have a question, start here.

New to this? Ask about a free Microsoft security review as a starting point.

What we can help with
  • Managed detection and response
  • Microsoft Sentinel engineering
  • Identity and email security
  • A free Microsoft security review
1You send a message
2A specialist replies within a business day
3We set up a call to scope what you need

"*" indicates required fields

This field is for validation purposes and should be left unchanged.