Frequently asked questions
- Which organizations are our pentest services for?
- Why is your application a target for hackers?
- Why choose DongIT as your pentest partner?
- What certifications do your pentesters hold?
- Is your work compliant with NIS2, DORA, DigiD or MIAUW?
- What is the difference between black-box, grey-box and white-box pentests?
- What are the advantages of manual testing methods?
- What is the difference between an OWASP Top 10 and NCSC report?
- Do you also perform pentests on mobile apps and APIs?
- Can you perform pentests in cloud environments (Azure, AWS or GCP)?
- What does a pentest cost?
- What is the best timing to perform a pentest?
- How often should I perform a pentest?
- What is the lead time for a pentest?
- Do you work with an NDA and how is my data protected?
- How do you prepare for a pentest?
- What information must be provided in advance for a pentest?
- Why pentest on an acceptance or test environment?
- Test and production on the same server: what is the risk?
- Why whitelist IP addresses during a pentest?
- Why adjust SMTP settings during a pentest?
- What are the advantages of a scan sensor?
- Can I see a sample report before I decide?
- What happens when critical vulnerabilities are found?
- Does a pentest guarantee 100% security of my application?
- How does an effective retest work?
- Can I get help fixing vulnerabilities?
- Can I share the report with auditors or customers?
Nederlands