Our pentests suit organizations from small businesses to enterprises, including online retailers, SaaS providers, healthcare organizations, public bodies and financial institutions. An assessment helps you evaluate security risks, prioritize improvements and provide technical evidence to customers, partners or auditors.
When is a pentest needed?
This depends on your risk profile, the systems you use and any contractual or legal requirements. An obligation to test security measures does not automatically mean every organization must commission an external pentest annually.
For a DigiD connection, technical testing contributes to the annual ICT security assessment. DORA sets risk-based testing obligations, with additional requirements for institutions designated for advanced threat-led testing. Under NIS2, GDPR and standards such as ISO 27001 or NEN 7510, the assessment must reflect the applicable requirements and risks. A pentest can contribute evidence but does not establish complete compliance on its own.
Useful even without a specific obligation
A pentest can also be valuable without a legal or contractual requirement. Examples include preparing an application for launch, assessing significant changes or responding to customers' requests for security evidence. Your objectives and the potential consequences of exploitation determine which components and attack scenarios deserve attention.
Which systems can we assess?
We assess web applications, mobile apps, APIs, networks, cloud environments and OT systems. A full code assessment is available as a separate source code review. During a free scoping call, we tailor the assessment to your situation.
View our pentest plans or discuss your assessment requirements with us.
Nederlands