Any application or system connected to the internet is a potential target. According to the Dutch National Cyber Security Centre (NCSC), one in five Dutch organizations experienced a cybersecurity incident in 2024. Automated scanners operated by criminals search the internet 24/7 for vulnerable systems. Large organizations and SMBs are not spared.
Why your application is a target
1. Direct financial gain
Ransomware, fraud and direct theft of funds are the biggest motivators. E-commerce platforms, banking applications, payment systems and any service handling financial transactions are high-value targets. According to Dutch Chamber of Commerce data, the average damage per ransomware incident in Dutch SMBs ranges from €10,000 to €150,000.
2. Valuable data
Personal data, medical records, financial details, customer databases and trade secrets are sold on criminal marketplaces or used for identity theft and targeted fraud. Intellectual property, proprietary software and research data are also attractive for competitive advantage or resale.
3. Stepping stone to connected systems
Your application may be an entry point to other systems: internal networks, integrations with partners or suppliers, cloud environments and administrative systems. Attackers use this lateral movement to penetrate deep into organizations, often unnoticed and over long periods of time.
4. Your infrastructure for other attacks
Compromised systems are used for cryptojacking (illegally mining cryptocurrency using your computing power), as part of botnets for DDoS attacks, or for sending spam and phishing emails. Your organization bears the costs and reputational risk while the attacker profits.
5. Reputation and competition
A successful attack leads to loss of customer trust, negative media coverage and declining revenue. Competitors or hostile parties may deliberately orchestrate this. For listed organizations, a single incident can directly impact share price and market value.
6. Social engineering and supply chain
Applications that handle user interactions (email services, portals, customer environments) are used for phishing and social engineering. If your organization is a supplier to essential entities under NIS2, your security automatically becomes part of their risk management. Supply chain attacks are growing rapidly because attackers reach multiple organizations at once through one weak supplier.
Why this is more relevant than ever
Since the Dutch Cybersecurity Act (NIS2) came into effect on 15 August 2026, fines of up to €10 million loom over organizations that cannot demonstrably prove their security is in order. DORA has required financial entities to conduct annual ICT testing since 17 January 2025. And GDPR holds organizations financially accountable for data breaches. Preventive pentests identify vulnerabilities before attackers do and provide demonstrable evidence of due diligence.
Small organization? Also a target
A common misconception: "We are too small to be interesting." Reality tells a different story. Smaller organizations are often specifically targeted because their security is less mature and they have access to larger partners in the supply chain. According to Statistics Netherlands (CBS), around 60% of Dutch SMBs faced a cyber threat in 2024.
Want to know where your application is vulnerable before attackers find out? Contact us for a complimentary scoping conversation, or view our pentest packages from €1,480.
Nederlands