View all pentests
Understand your organization’s security
A pentest reveals how attackers could exploit vulnerabilities in your application, network or IT environment. Our ethical hackers tailor the assessment to your objectives and risk profile. You receive a clear report with practical recommendations to improve your security.

When do you need a pentest?
Before launch or after changes
Assess whether new applications, features or integrations introduce vulnerabilities.
For an audit or client request
Provide evidence of your technical security through an assessment aligned with the agreed requirements.
To understand your risks
Discover which attack paths could affect your critical systems and sensitive data.
Pentests by environment
Your objectives, risk profile and the systems you want to assess determine which pentest is appropriate. During the scoping conversation, we advise you on the type or combination that best fits your situation.
Web application pentest
Pentesting for web applications, APIs and SPAs based on OWASP ASVS. Focus on business logic, authentication and multi-tenant separation.
Network and cloud pentest
External and internal network pentesting including Azure, AWS, M365 and Entra ID. Assumed breach scenarios and Active Directory testing.
OT security pentest
Pentesting for PLCs, SCADA and industrial networks aligned with IEC 62443 and the Purdue model. Without disruption of production continuity.
Additional security services
For additional security needs, we also offer code reviews, vulnerability scans and phishing simulations.
Phishing and awareness
Controlled phishing simulations and awareness measurements. Suitable for NIS2 reporting and cultural change.
Source code review
Manual code audit for secure coding, business logic and cryptographic implementations. Complements black-box pentesting.
Vulnerability scan
Automated scanning as a supplement to periodic pentesting. For continuous monitoring between assessments.
The expertise of DongIT is beyond doubt, the cooperation is enjoyable and they meet their agreements.
Aloysius Foundation
What makes our pentests different?
Automated scanners find known vulnerabilities. Our pentesters find what scanners cannot see: business logic flaws, tenant separation issues, complex race conditions, IDOR patterns, cross-tenant leakage and the creative exploit chains real attackers actually use.
By testing in a targeted, context-aware way within the engagement scope, we do more than identify vulnerabilities in isolation. We chain them together for deeper insights that only emerge when experienced people piece the puzzle together. Read more about the benefits of manual testing.
Four eyes on every finding. Every pentest is delivered under our four-eyes principle: minimum of two testers involved per engagement, with peer review on every finding. For supervisory authorities (DNB, AFM, IGJ, Dutch Data Protection Authority) and auditors, this practice combined with the CCV Keurmerk Pentesten accreditation is an additional quality indicator that strengthens your compliance reporting. As an ISO 27001:2022-certified organization ourselves, we know how an audit works from the inside.
Our process from scope to report
Transparent, predictable and without surprises. Six steps from the first conversation to the final report. We always align our reporting with the compliance framework that is relevant to you.
Intake
Complimentary conversation to map out your architecture, threat model and compliance goals. No obligation.
Complimentary, 45 to 60 minutes
Tailored quotation
You receive a concrete proposal with scope, methodology, planning and investment. Fixed price, no hidden costs.
Within 3 business days
Preparation
We arrange access, set up safety agreements and prepare test environments together with your IT and development teams.
1 to 2 weeks
Execution
Manual testing by at least one certified pentester. Larger engagements use teams of two to three testers with regular progress updates.
5 to 25 business days depending on scope
Report
You receive your report through our own Security Reporter platform, with an executive summary, technical findings with CVSS scores and practical remediation guidance. The data stays in Europe.
Within 5 business days after execution
Retest
Once you have resolved vulnerabilities, we validate that the remediation actually works. Time and materials, based on the number and complexity of findings.
Time and materials
Pentest types: black box, gray box or white box?
Which form of pentest works best depends on your objective, threat model and available information. The forms differ mainly in how much prior knowledge, test accounts and background information the tester receives upfront.
The form is determined in consultation with you, based on the situation, requirements and intake process.
- Black box pentest. Tester has minimal prior knowledge. The most realistic simulation of a real-life hack.
- Gray box pentest. Tester has partial information such as user accounts.
- White box pentest. Tester has full insight into all aspects of the system architecture and access to the source code. This produces the most thorough findings.
- Time-boxed or budget-boxed pentest. Testing where the duration or budget determines when the test ends.
Our methodology: internationally recognized frameworks
An effective pentest goes beyond finding vulnerabilities. It is about insight, impact and actionable remediation. Our approach is based on internationally recognized frameworks, and we actively apply the latest developments, zero-day vulnerabilities and current attack techniques in our security engagements.
- NIST Cybersecurity Framework. Risk management and best practices for IT security.
- OWASP Testing Guide and ASVS. Testing web applications against the most critical vulnerabilities.
- PTES and OSSTMM. Standards for in-depth and structured penetration testing.
- ISSAF. Assessment framework for systems and networks.
- IEC 62443. For OT environments and industrial control systems.
- NCSC guidelines. Dutch best practices for security testing.
What does a pentest cost?
The price depends on scope and complexity. For clearly defined engagements we offer standard packages. For more complex engagements we work with a scoping conversation and a tailored quotation.
- Quick Pentest, €2,960 excl. VAT
- Expert Pentest, from €5,040 excl. VAT (most chosen)
- Extensive Pentest, from €7,200 excl. VAT
- Enterprise engagements, tailored quotation
Tailored pricing
For every complex engagement we first propose a complimentary scoping conversation. This ensures you know exactly what the investment will be and what to expect. See our pentest cost and plans for the fixed and starting prices.
Frequently asked questions about pentesting
Below are the most frequently asked questions about pentesting. For a complete overview please visit our FAQ page.
What exactly is a pentest?
A pentest, also known as a penetration test or ethical hacking engagement, is a security assessment in which certified ethical hackers test your systems and applications for vulnerabilities. In the same way malicious hackers would. The goal is to identify and fix weaknesses before they can be exploited.
Which pentest do I need?
That depends on the objective of the pentest, your risk profile and the systems you want assessed. For example, do you want to assess a new application, identify potential attack paths or provide evidence of technical security for an audit? Together with the sensitivity of your data and the potential consequences of exploitation, this determines the components, test scenarios and depth of testing required.
A web application pentest may be appropriate for a web application or SaaS platform, a network and cloud pentest for your IT infrastructure, and an OT security pentest for industrial environments. During scoping, we recommend the assessment or combination of assessments that best fits your objectives and risks.
Which pentest helps reduce the risk of ransomware?
A network and cloud pentest is often a suitable starting point. An external pentest examines potential entry points from the internet. An internal pentest examines what an attacker who already has access could reach, for example through a compromised user account. We assess access permissions, network segmentation and access to critical systems.
We tailor the assessment to your risk profile and IT environment. You receive practical recommendations to interrupt attack paths and limit potential damage. No pentest can fully prevent ransomware: fixing vulnerabilities, strong access controls, monitoring and tested, protected backups remain essential.
How long does a pentest take?
Active testing time ranges from 16 hours for a small web application to 80 hours or more for a large network or enterprise web app pentest. Total duration from scoping conversation to final report is typically 4 to 8 weeks.
What is the difference between a pentest and a vulnerability scan?
A vulnerability scan largely automates checks for known vulnerabilities and configuration errors. A pentest adds manual investigation, for example of business logic, authorization and combinations of vulnerabilities. The choice depends on your objectives, risk profile and any specific audit or contractual requirements. A scan does not replace a pentest where one is explicitly required.
How often should I have a pentest performed?
This depends on your risk profile, changes to your systems and any audit or contractual requirements. Annual testing can be a useful starting point, with additional assessments after significant changes. This is not a universal legal pentest requirement. DigiD requires an annual ICT security assessment; align the pentest and follow-up with the applicable requirements.
Will a pentest disrupt our production environment?
We prefer to work on acceptance or test environments. Where production testing is necessary, we make strict safety agreements about timing, impact limits and escalation paths. Our testers know how to work without disruption.
What about compliance mapping?
We can map findings to the relevant technical requirements of your framework, for example for NIS2, ISO 27001 or DigiD. We agree the requirements, systems and reporting components in scope beforehand. The report provides technical evidence for your auditor, but is not a certification or a guarantee that your organization meets every requirement.
Ready to demonstrate your security?
Preparing for an audit? Meeting client or contract requirements? Rolling out a new application? Response within one business day. Quotation within three business days.
Nederlands