What is ITDR — in one sentence?
ITDR (Identity Threat Detection and Response) watches your user accounts the way EDR watches your devices: suspicious sign-ins, covert mailbox rules and taken-over accounts get detected, stopped and assessed by an analyst team.
Why this may be the most important block today
The modern attacker does not break in — they log in. Credentials from phishing, data leaks or intercepted sessions are the most common way into mid-sized companies. And the most expensive variant is unspectacular: the attacker takes over a mailbox, reads along for weeks, sets an inconspicuous forwarding rule — and strikes exactly when a real invoice is due. Only the bank account is different. This fraud (business email compromise) has caused higher losses than ransomware for years — it is just quieter.
And MFA? Essential, but not the end: fatigue attacks, intercepted session tokens and phished codes bypass it regularly. MFA makes the attacker’s login harder — ITDR notices when it succeeded anyway.
Who needs it?
- Every company that instructs or approves payments via email — classic BEC hits finance and management.
- Every company on Microsoft 365 or other cloud accounts: the identity is the master key to mail, files and Teams.
- Companies with remote access and external providers — more accounts, more doors.
What we take on
- Connecting your user accounts to identity monitoring — without touching daily work
- 24/7 assessment of suspicious sign-ins and rule changes by the analyst team
- Immediate action on takeover: end sessions, secure the account, remove malicious rules — then the debrief with you
- Interplay with access order and user administration: clean accounts are half the defence
Billing
Per user account per month, as its own position — like every block. Typically combined with endpoint protection: device and identity are the two ways in, and both deserve a guard.
FAQ
We have MFA — is that not enough? MFA is mandatory and stays so. But it only checks the moment of login. ITDR watches what happens after: the sign-in from two countries within an hour, the new forwarding rule at midnight, the sudden mass download. One does not replace the other.
Is someone reading our mail? No. What is monitored are sign-in events, configuration changes and permissions — not your content.
What happens on a detected takeover? The account gets secured immediately — sessions ended, access locked, malicious rules removed. Then we clarify together: what was reached, who must be informed, what prevents a repeat.