Cybersec Netherlands
Took a trip to Cybersec Netherlands to find more EU-centric companies, this is who I talked with
Joe Garifo
9/14/20264 min read


Last week I hopped on a train and went over to Utrecht for the day to check out the Cybersec Netherlands Expo. I went in search of companies to support my plans of helping companies build an EU sovereign security stack. That means either EU built or open-source tools that aren't controlled by the US tech industry. And Cybersec Netherlands was focused on that too. I made sure to stop at booths that focused on that in the categories I needed. So let's talk about what I saw and the three thing I wanted to see but didn't.
The first booth I stopped at and spent a good amount of time talking with someone about is ESET. I've known of ESET for as long as I've been in the industry, which makes sense as they've been around for almost 35 years now. I've never worked with ESET, but I have always respected the threat intel research they put out on threat actors. They have a full XDR platform now, with vulnerability management and patching, disk encryption, cloud app and workload protections, and the usual EDR capabilities. They just launched a marketplace for integrations that they are working on expanding out. ESET really feels like the backbone of the MSSP offering I am thinking of.
Next was NinjaOne, they unfortunately are not an EU based company, but does have a German headquarters. I don't believe that does enough to protect European data from US government subpoenas. NinjaOne is a Remote Monitoring and Management tool that does everything. They have integrations with Okta, InTune, SentinelOne, Crowdstrike. They're the glue that holds modern IT infrastructure together. And just from the names I listed from integrations, you can tell it's very US-centric. I have experience with NinjaOne, it's a very good platform but just not the tool I am looking for in a EU data sovereign plan.
Walking down an aisle, I came across Myra, a German DDoS protection company. They have a section on their site about EU digital sovereignty, so that's a big points in my book. They have all the same offerings as Cloudflare, DDoS protection, CDN, WAF, Captchas and even an on-prem solution for DDoS. While this would not be a standard offering for customers, I am not planning on targeting companies that need this right away, it's a good offering to have in case someone asks about it.
I got a chance to stop and talk with Uniqkey, an EU Password Manager for businesses. I've been looking for a new password manager after 1Password leaned into proudly supporting right-wing developers, but that's a blog for another day. Uniqkey is just for businesses though, I do not see a personal offering for their platform and they didn't have demos there, but they slot in very nicely into the password manager category, especially without having the need for enterprise level contract to get SSO like many other tools do. I'll see about scheduling a demo with them in order to see things in action.
I worked at Tenable for six years, used the tools the whole time. In the US, Tenable is one of those tools that used to be referred to specifically by name in security requirements along with Sourcefire. Greenbone is the company that manages OpenVAS, a fork of Nessus from back when it was open-source. Like many companies that have spun up around open source products, you can get the main tool for free and run it how you like in your environment, but signing up for a contract with Greenbone will give you support, professional services and additional intel feeds. They are EU based on top of being open source, which is very awesome. If a customer needed just the VM offering and not the full suite offering of ESET, Greenbone is the tool I am turning to.
Lastly I came across Evertrust, a French PKI and Cert lifecycle management company. They've built a very cool tool that helps manage private certs and PKI for companies. Much like Myra, this is not a tool that slots into the workflow of small orgs that I am interested in working with at the start, but could definitely be of value down the line for larger orgs.
So what did I want to see that wasn't there? EU based TLS cert provider. I have found a few online, like Actalis out of Italu, Certum out of Poland and Harica out of Greece. Still would have liked to have seen a provider there. Second was SSO, did not see any SSO providers. I have found a number of providers who run Keycloak instances for you, but Keycloak is a RedHat project, and after what happened to CentOS, I'm reluctant to use future offerings from them. Hanko and cidaas out of Germany are the two providers I'm going to be looking into. And finally is an EU firewall provider. I know pretty much all manufacturing of hardware is coming out of China and Taiwan, an issue even US tech companies have, but I have seen StormShield out of France I'd really love to get a look at their interface and play around with it.
Cybersec Netherlands 2026 is in the books and I'm hoping for 2027, I am going with more intent to purchase and make partnerships than I was this year. If you're a small to midsized business in the Netherlands, or even broader Benelux, and you want to talk MSSP support, reach out, let me know and lets find a solution that fits your needs!