Get a network and cloud pentest
Your external network and cloud environment are often the first route for attackers into internal systems and sensitive data. Whether you are preparing for a compliance audit, migrating to Azure or AWS, or simply want certainty about your network segmentation: a network pentest gives you demonstrable insight.
With an external and internal network pentest, DongIT maps out vulnerabilities and misconfigurations in a controlled way. In practice, organizations rarely have full visibility into their online exposure. Forgotten subdomains, unused hosts and legacy configurations expand the attack surface without you noticing.
Our pentests are performed by OSCP and OSEP-certified ethical hackers under our four-eyes principle. Reporting via our self-developed Security Reporter platform. CCV Keurmerk-accredited. Data stays in Europe.
What we test in a network pentest
A network pentest fully maps out your external and internal network and the associated services. The goal is to identify vulnerabilities, misconfigurations and unnecessary exposure that could lead to unauthorized access to your IT environment.
Depending on your objective and risk profile we perform an external, internal or combined network pentest, typically supplemented with a cloud pentest for organizations with a cloud or hybrid architecture.
- External perimeter. Publicly reachable hosts, VPN endpoints, mail servers, web servers, firewalls and cloud endpoints. Test what an attacker sees and can reach from the internet.
- Internal networks. On-site testing of internal infrastructure, network segmentation and access controls. Often from an assumed breach scenario: what can an attacker do who is already inside?
- Cloud infrastructure. Azure, AWS, GCP and Microsoft 365. Configuration, identity models and access risks.
- Active Directory and Entra ID. Configuration, delegation, group policies, hardening and common AD attack techniques.
- Wireless and VPN. Wireless networks, guest networks and remote-access solutions.
For operational technology (OT) and industrial environments we offer a separate OT security pentest per IEC 62443. Network pentests are often combined with a phishing or social engineering test to also assess human attack vectors.
Our approach: how we test your network
We approach your network the way an attacker would. From passive reconnaissance to active exploitation, with continuous alignment on impact and safety.
Identification of domains and IP addresses
We map out all domains, subdomains and IP addresses directly or indirectly linked to your organization. Often we find forgotten environments here that were no longer on anyone's radar.
Open Source Intelligence (OSINT)
Analysis of publicly available information such as search engine indexes, leaked credentials, document metadata and social media. This passive reconnaissance happens without interacting with your systems: no load, no detection noise, no impact on your operations.
Analysis of systems and services
Investigation of open ports, active services, outdated software and misconfigurations on all identified systems.
Analysis of attack vectors
Identification of possible external and internal attack paths, with focus on access controls and known vulnerabilities. For internal networks we often work from an assumed breach scenario to reveal realistic paths toward your crown jewels.
Controlled exploitation
Where safe, we test whether identified vulnerabilities are actually exploitable. In consultation with you and with strict agreements on impact and escalation paths.
Reporting and retest
Delivery via Security Reporter with executive summary, technical findings (CVSS-scored) and concrete remediation guidance. Retest of resolved vulnerabilities on time and materials.
Cloud infrastructure pentest: what we focus on
Cloud environments have different attack patterns than traditional networks. Our cloud pentests provide insight into configuration errors, access risks and compliance deviations at the points that really matter in cloud context.
- Cloud configuration. Detection of common misconfigurations in Azure, AWS and GCP, from open storage buckets to leaky security groups.
- Identity and Access Management. Analysis of user permissions, MFA implementation, privilege escalation paths and service accounts.
- Entra ID hardening. Conditional Access, hybrid identity, delegation, guest access and common Microsoft 365 attack vectors.
- Data encryption. Evaluation of encryption at rest and in transit, key management and access to encryption keys.
- Logging and monitoring. Assessment of detection and incident response capabilities within your cloud environment.
- Resilience and recovery. Testing of backups, failover and recovery procedures against scenarios such as ransomware.
Compliance mapping for network and cloud
Our reports are always aligned with the compliance framework relevant to you. Findings are explicitly linked to the relevant controls, so you have direct evidence for your auditor or supervisory authority.
NIS2 and Dutch Cybersecurity Act
Demonstrable assessment of security measures per article 21 Dutch Cybersecurity Act. Especially valuable for essential and important entities with complex network infrastructure.
ISO 27001
Testing of technical controls from Annex A.8.8, A.8.20, A.8.21 and A.8.22. Evidence for your ISMS and external audit.
BIO2
For Dutch government organizations. Network pentest per Baseline Informatiebeveiliging Overheid 2, directly usable for ENSIA reporting.
DORA
For financial entities. Network pentest per DORA articles 24-27 and preparation for Threat-Led Penetration Testing (TIBER-NL).
IEC 62443
For organizations with OT infrastructure. Network segmentation testing between IT and OT per Purdue model. See our separate OT pentest for full industrial engagements.
DigiD connections
For municipalities and government organizations with DigiD integration. Network component of the DigiD security assessment.
What does a network pentest cost?
The price depends on the size of your network, the number of in-scope hosts and whether on-site or cloud testing is included. For clearly defined engagements we offer standard packages. For more complex engagements such as large enterprise networks or hybrid cloud environments we work with a scoping conversation and a tailored quotation.
- Quick Pentest, €2,960 excl. VAT
- Expert Pentest, from €5,040 excl. VAT (most chosen)
- Extensive Pentest, from €7,200 excl. VAT
- Enterprise engagements, tailored quotation
Tailored pricing
For every complex engagement we first propose a complimentary scoping conversation. This ensures you know exactly what the investment will be.
Frequently asked questions about network pentesting
Below are the most frequently asked questions about network and cloud pentesting. For a complete overview please visit our FAQ page.
What is the difference between an external and internal network pentest?
An external pentest tests what an attacker can reach from the internet without first gaining access: publicly reachable systems, VPN endpoints and cloud endpoints. An internal pentest tests what can happen when an attacker is already inside, for example via a compromised workstation. For full insight we recommend both.
What is an assumed breach pentest?
In an assumed breach pentest we assume the attacker is already inside, for example via phishing. From that position we test whether segmentation works, whether privilege escalation is possible and how far an attacker can move toward crown jewels. This approach is more realistic than external testing alone.
What about Active Directory and Entra ID testing?
AD and Entra ID testing are typically part of an internal network or cloud pentest. We test common attack techniques such as Kerberoasting, ASREPRoasting, DCSync, delegation abuse, attacks on group policies and Microsoft 365 vectors such as consent phishing and token theft. We also assess hardening and detection capabilities.
What is the difference between a network pentest and an OT pentest?
A network pentest focuses on regular IT infrastructure: servers, networks, cloud, Active Directory. An OT pentest focuses on operational technology: industrial control systems, PLCs, SCADA and related environments. Methodologies and safety requirements differ substantially. For organizations with both we often offer combined engagements with separate scoping.
How long does a network pentest take?
Active testing time ranges from 32 hours for a small external pentest to 80 hours or more for extensive internal and cloud environments. Total duration from scoping conversation to final report is typically 4 to 8 weeks.
Will a pentest disrupt our network?
Our pentesters are trained to work without disruption. For potentially impactful tests such as denial of service, aggressive credential brute-forcing or specific exploits we make strict agreements upfront about timing, impact limits and escalation paths.
What do I provide as input?
Depending on scope: for external pentest often only your domain name. For internal pentest a network diagram, VLAN overview, credentials for a regular user (assumed breach) and access to a test workstation or deployed device. For cloud pentest a read-only IAM account or Cloud Access role.
Is a retest included?
Retest of resolved vulnerabilities is performed on time and materials, depending on the number and complexity of findings. This is discussed during intake and explained in the quotation.
Ready to have your network and cloud tested?
Preparing for an audit? Migrating to the cloud? Want to know whether your segmentation would stop a real attacker? Response within one business day. Quotation within three business days.
Nederlands