Frequently asked questions

  1. Which organizations are our pentest services for?
  2. Why is your application a target for hackers?
  3. Why choose DongIT as your pentest partner?
  4. What certifications do your pentesters hold?
  5. Is your work compliant with NIS2, DORA, DigiD or MIAUW?
  6. What is the difference between a vulnerability scan and a penetration test?
  7. Is a network scan or vulnerability scan sufficient security?
  8. What is the difference between black-box, grey-box and white-box pentests?
  9. What are the advantages of manual testing methods?
  10. What is the difference between an OWASP Top 10 and NCSC report?
  11. Do you also perform pentests on mobile apps and APIs?
  12. Can you perform pentests in cloud environments (Azure, AWS or GCP)?
  13. What does a pentest cost?
  14. What is the best timing to perform a pentest?
  15. How often should I perform a pentest?
  16. What is the lead time for a pentest?
  17. Do you work with an NDA and how is my data protected?
  18. How do you prepare for a pentest?
  19. What information must be provided in advance for a pentest?
  20. Why pentest on an acceptance or test environment?
  21. Test and production on the same server: what is the risk?
  22. Why whitelist IP addresses during a pentest?
  23. Why adjust SMTP settings during a pentest?
  24. What are the advantages of a scan sensor?
  25. Can I see a sample report before I decide?
  26. What happens when critical vulnerabilities are found?
  27. Does a pentest guarantee 100% security of my application?
  28. How does an effective retest work?
  29. Can I get help fixing vulnerabilities?
  30. Can I share the report with auditors or customers?