The prevailing debate in cybersecurity centres on how organisations defend themselves against attackers who use AI. But there is another side to this story: a range of Dutch startups is building AI technology as the foundation of their own security products. They detect fraud, monitor networks, analyse financial risk and protect infrastructure, and they do so with models that recognise patterns human analysts miss or only catch later.
Together, these companies have now raised more than 300 million euros in funding. They operate in sectors that have traditionally struggled with scalable detection: banking, insurance, critical infrastructure and compliance. The fact that the Netherlands has produced its own players across all of these domains speaks to the breadth of the ecosystem.
Detecting fraud before damage occurs
The two most heavily funded examples in this segment focus on financial fraud. FRISS, founded in 2006 in Utrecht, automates fraud detection for property and casualty insurers. In 2024 the company raised a Series B round of 59.4 million euros, bringing total funding to a comparable level. FRISS targets the moment of claims assessment and underwriting: algorithms evaluate whether a claim or application displays suspicious behaviour before a human employee ever looks at it.
ThreatFabric from Amsterdam addresses a different part of the fraud problem. The company detects malware and fraudulent sessions in online banking for a customer base of around 60 million end users. Its approach is behavioural: models analyse how a user interacts with a banking app and flag deviations from what is normal for that specific user. In 2024 ThreatFabric raised 11.5 million euros in a seed round, a relatively modest sum for a company that has been active for ten years, pointing to a deliberate growth discipline.
Both companies operate in an environment where attackers also use AI to evade detection. Their models must therefore not only recognise static patterns, but also adapt to constantly evolving attack methods.
Compliance and KYC as a data-intensive problem
Vartionfounded in 2018 in Amsterdam, focuses on a different type of risk: screening individuals and entities for KYC and AML purposes. Financial institutions are legally required to verify who they do business with, but the volume of relevant data, sanctions lists, court rulings, politically exposed persons and international corporate structures, is too large to monitor manually. Vartion builds AI-driven search engines that comb through this data and identify connections. In 2022 the company closed a Series B round of 9.7 million euros.
What is notable about Vartion is that it does not treat compliance as a checkbox exercise, but as an information retrieval problem. The question is not merely whether someone appears on a list, but what connections exist between entities that may each individually go unnoticed.
Network monitoring and physical infrastructure
Security extends beyond the financial sector. OPT/NET from Bergen builds an AIOps platform that monitors and manages complex critical networks. The platform analyses network traffic in real time and detects anomalies that may indicate outages or attacks. Founded in 2018, the company has raised 500,000 euros in a pre-seed round to date, indicating that it is still in the early stages of its funding journey.
LUGN Security from Heerlen combines sensors, drones and AI for the surveillance of large sites and infrastructure. Founded in 2021, the company had already raised 36.8 million euros in a Series B round by 2022, an unusually high amount for such an early stage. This points to a capital-intensive product in which hardware, data infrastructure and AI software converge. Physical site surveillance has traditionally been labour-intensive; automated detection via drones and sensors can make it scalable.
Privacy-preserving collaboration on risk models
A specific challenge in AI-driven security is data: good models require large amounts of training data, but that data is often sensitive and cannot simply be shared. Roseman Labs from Utrecht builds technology that enables organisations to collaborate on sensitive data without actually exchanging it. The approach is based on cryptographic techniques such as secure multi-party computation.
For the security sector this is relevant because fraud patterns often only become visible when multiple institutions combine their data, but banks and insurers compete with one another and are bound by privacy legislation. Roseman Labs raised a Series A round of 9.4 million euros. The company was founded in 2020 and focuses on an infrastructure layer that enables other AI applications.
Computing power as a prerequisite
Separate from the detection logic itself is the question of where the computing power comes from. Planck Network, founded in 2023 in Amsterdam, builds a decentralised GPU network for training and deploying AI models. In 2025 the company raised 200 million euros in a Series B round. While Planck Network is not a security company in the traditional sense, it is relevant to this ecosystem: security models that must run in real time on large data streams require substantial computing power, and the availability and cost of GPU capacity are a direct factor in the viability of AI-driven security.
The breadth of this Dutch landscape, spanning fraud detection and compliance to network monitoring and privacy technology, shows that AI in security is not a monolithic theme. Each application requires domain knowledge, specific datasets and its own approach to model maintenance. For investors and policymakers seeking to understand the Dutch tech ecosystem, security is a segment that has gained weight both in capital terms and in technical depth.