Yes. In addition to performing pentests, DongIT can support you in resolving findings. This is a separate service alongside the pentest itself and is tailored to your tech stack, complexity of findings and available capacity within your own team.
Forms of remediation support
- Remediation guidance in the report. Standard for every pentest: our pentesters provide concrete advice per finding for how to resolve it, including code examples where relevant. This is included in all packages.
- Consultancy per finding. On an hourly basis you can consult our pentesters for extra explanation, alternative solution strategies or validation of your intended fix before implementation.
- Code review of fixes. We review your proposed code changes and provide feedback before production deployment. This is more efficient than waiting for the retest.
- Active remediation implementation. For complex or time-sensitive findings, DongIT can implement the fix directly in your codebase, in consultation with your development team. This suits organizations without in-house security development capacity.
- Ongoing engagement. For organizations with continuous need for security expertise we offer retainer agreements in which our pentesters are available on call.
Tech stacks we support
Our pentesters have hands-on development experience across a wide range of technologies. We support remediation in:
- Backend. PHP (Laravel, Symfony), Node.js (Express, NestJS), Python (Django, Flask), Java (Spring Boot), .NET (Core, Framework), Ruby on Rails.
- Frontend. React, Vue, Angular, plus vanilla JavaScript and TypeScript.
- Mobile. Native iOS (Swift, Objective-C), native Android (Kotlin, Java), cross-platform (React Native, Flutter).
- Infrastructure. Kubernetes, Docker, Terraform, cloud-native on Azure, AWS and GCP.
- Database. Relational (MySQL, PostgreSQL, SQL Server, Oracle), NoSQL (MongoDB, DynamoDB, Cosmos DB).
Does your application run on a tech stack not listed? Discuss it during the scoping conversation. We likely can support that too.
What is included and what is not
Distinction between remediation support and longer development projects:
- Included in remediation support: security fixes for identified vulnerabilities, code review of your fixes, secure coding advice, architectural suggestions for security improvement.
- Not included: feature development, migration projects, general refactoring, performance optimization or other non-security related work. For these services we refer you to our DongIT main website where we offer our broader development services.
How do I start remediation support?
Remediation support is delivered on request, typically after delivery of the pentest report. Contact us as soon as you know which findings need support. We prepare a tailored quote based on scope, complexity and desired lead time.
Contact us for a complimentary scoping conversation, or view our pentest packages.
Nederlands