We didn’t adopt Zero Trust. We helped build it.
Since 2005, ON2IT has treated Zero Trust as a strategy to operationalize, not a product to sell. Today that strategy runs 24/7 across North America and Europe, built on our own platform and delivered by our own team.
A strategy first. A company built to run it.
ON2IT was founded in 2005 by Marcel van Eemeren and Lieuwe Jan Koning, who lead the company today in the same roles they started in. That continuity shapes how we work: Zero Trust isn’t a campaign we ran once, it’s the strategy we’ve spent two decades operationalizing for organizations that can’t afford to get security wrong.
We are a pure-play cybersecurity provider: security is the only thing we do, not one line item alongside networking, hardware, or general IT support. Everything we build, staff, and improve is aimed at one outcome: making Zero Trust real inside your environment, every day, without you having to run it yourself.
We start by helping you build the roadmap: what to protect first, in what order, and what “good” looks like for your organization. That focus is then delivered through MDR Prevent™: our in-house AUXO™ platform, a 24/7 GSOC that never stops watching, and a team that treats your Protect Surface as if it were our own.
We don’t believe in legacy MDR. Detect-and-respond alone is a strategy that’s already lost. We build for prevention first.
Marcel van Eemeren & Lieuwe Jan Koning — Co-founders, ON2IT, 2005 to today
Still the same two people, twenty years in
Marcel van Eemeren and Lieuwe Jan Koning founded ON2IT in 2005 and still lead it today, in the roles they started in. That’s rare in cybersecurity, where founders sell, get acquired, or move on. It’s also why the strategy hasn’t drifted: the people who committed to Zero Trust in 2005 are the same people accountable for it now.
We hold an unyielding commitment to anti-fragile cybersecurity.
We innovate and deliver Zero Trust, the global benchmark for protecting the digital fabric.
Built to move at the edge, not just at the top
The team closest to a client is the team that decides. A GSOC analyst who spots an attack doesn’t wait for sign-off to contain it. A consultant scoping a client’s Protect Surface doesn’t wait for a committee to approve the plan. Decisions get made by the people who can see the problem, not passed up a chain until someone further away signs off.
What keeps that consistent across every team is what we build everything else on: one strategy, Zero Trust, and one platform, AUXO™. A client in Dallas and a client in London get the same standard, the same GSOC discipline, and the same platform, even though the people and the day-to-day differ market to market.
AI is part of how that team works now, not just what we sell. It gives every analyst and every consultant more speed and more context. It does not change who is accountable for the outcome: every deliverable that leaves ON2IT is still checked, verified, and owned by a person.
AI changes our speed. It doesn’t change why we work, or what “good” looks like.
Zero Trust isn’t a technology you buy. It’s a strategy you commit to.
The strategy, from the source
We were one of the first companies in the world to build a managed service around Zero Trust, working alongside John Kindervag on the framework since 2013. That partnership deepened when John formally served as ON2IT’s SVP Cybersecurity Strategy, shaping how we apply his framework in practice.
That gives ON2IT something most providers can’t claim: the person who defined Zero Trust, shaping how we apply it. It’s also why regulators and industry bodies come to us rather than the other way around. Our contributions sit inside the 2022 U.S. NSTAC Report to the President on Zero Trust and the World Economic Forum’s cybersecurity action group.
Zero Trust, done properly, isn’t a bolt-on control. It’s an architecture decision that makes your security posture independent of any single vendor, tool, or piece of hardware, and it’s the reason our clients stay with us: average retention sits around 97%.
Four pillars. One outcome.
We don’t hand you a dashboard and a phone number. We run the strategy for you, on our platform, with our people, and increasingly, with our own AI working alongside them.
AUXO™, built by us
AUXO™ is ON2IT’s own Zero Trust platform: the control plane that correlates threat data, holds your Protect Surface, and gives you a live view of your security posture. It’s the same IP the European Commission recognized with a Seal of Excellence in 2019, and it’s why we’re not dependent on a third party’s roadmap.
A 24/7 GSOC that scales with the threat
Our Global Security Operations Center runs five shifts, around the clock, handling over a billion events a month. It’s the human judgment behind every prevention and every response, freeing your team from having to hire, train, and retain that capability in-house.
A Security Special Service Team, expert-led
For over 20 years, our Global SOC has delivered 24/7 human expertise from the best 10% in cybersecurity: screened, trained, and trusted worldwide. No junior analyst trains on your incident. Your own CSIRT stands by, drawn from our SOC, CSS, PSS, and CISO teams.
Strong AI adoption, on infrastructure we control
Our AI agents work the way our GSOC analysts do: faster with more context, and smarter with more human oversight. It runs on ON2IT-owned infrastructure, not a third-party model with your data flowing through it. AI-native by design, not bolted on afterward.
Worldwide, ON2IT has had the most successful Zero Trust implementations.
Their cybersecurity vision, maturity, and experience have accelerated our journey to Zero Trust.
Why Zero Trust wins the AI era
AI hands attackers machine speed, but it doesn’t create new doors. It just moves faster through the ones already left open. Zero Trust is the one answer that doesn’t care how fast an attacker is: you cannot traverse a path that does not exist. We remove the path, prove it holds, and run that around the clock.
Measures it
Continuous proof that every control actually holds, across IT, OT, and cloud, not a point-in-time audit.
Runs it, 24/7
Cases handled around the clock, so the absence of an attack path stays the absence of an attack path.
Removes the path
Not faster detection alone. Attack paths taken away before they can ever be used.
“The MDR you wish you had.”
Our AI runs on infrastructure we own, not a third-party model with client data flowing through it. AUXO Curator™ triages what an event means and how serious it is in seconds. EventFlow™ moves that signal at machine speed, end to end. The Zero Trust Dynamic Block List™ blocks the large majority of threats at the very first line of defense, before they reach a human at all.
A strategy we’ve stayed with
ON2IT is founded
Founded by Marcel van Eemeren and Lieuwe Jan Koning.
Palo Alto Networks partnership
Partnership with Palo Alto Networks begins.
ISO 27001 certified
ON2IT receives its ISO 27001 certification for information security management.
EC Seal of Excellence
AUXO™'s SOC-capability IP earns an EC Seal of Excellence. US office opens.
Kindervag joins, SOC 2 certified
John Kindervag formally joins as SVP Cybersecurity Strategy. SOC 2 certified.
20+ years, 300+ clients
20+ years in cybersecurity. 300+ clients across North America and EMEA.
Built for North America and EMEA
ON2IT runs as one company across two regions. Client data and detection stay in-region: a sovereign GSOC in North America, a sovereign GSOC in Europe, both built on the same platform and the same standard.
Looking for ON2IT in the Netherlands? Visit on2it.nl for Dutch-market content, services, and contact details.
ISO 27001
Certified since 2015
SOC 2 Type 2
Certified since 2021
Palo Alto Networks
Partner since 2009
EC Seal of Excellence
Awarded 2019
NSTAC & WEF
Zero Trust advisory, 2022
Gartner
“The MDR you wish you had”
The literature
Cited in George Finney’s books