References & Cases
What our clients
say — and what we found.
Confidentiality is a core value. All cases are anonymised and approved for publication. The findings and approach are authentic.
Completed assignments
Three cases — three sectors.
A growing SaaS company with a B2B project-management platform for around 80 business customers requested a grey box web application pentest, including API, ahead of an enterprise tender.
A Broken Object Level Authorization (BOLA) vulnerability in the API made it possible, as a logged-in user, to retrieve data from other organisations by modifying the object ID in the request. All customer data was accessible without additional privileges.
Vulnerability patched, authorisation checks implemented on all API endpoints. Retest confirmed correct remediation. Tender completed successfully.
A Dutch municipality with a DigiD-integrated citizen portal needed to submit an annual ICT security assessment to Logius under the NIBAD standard, with a tight submission deadline.
A session-handling misconfiguration left expired session tokens valid after logout. In addition, adequate logging of authentication attempts was missing — a direct compliance shortfall for Logius.
Both findings resolved before the deadline. Report submitted fully compliant with NIBAD. The municipality subsequently signed an annual testing agreement.
A specialised healthcare provider with around 200 staff and an EHR integration commissioned a combined vulnerability scan and grey box pentest in preparation for NEN 7510 certification.
Outdated software versions on internal servers, unsecured admin interfaces reachable via the internal network, and insufficient segmentation between the care environment and general IT infrastructure — together a high risk of unauthorised access to patient data.
A quarterly priority plan was drawn up. After three months of remediation a retest was performed. The report was used as the basis for the NEN 7510 certification process.
Wat opdrachtgevers zeggen
In their own words.
Our team hadn’t expected a critical flaw to be found so quickly. The report was clear, even for our non-technical management. The collaboration was direct and pleasant — no hassle.
We had a tight deadline for Logius. MonkeysICT delivered on time, the report was complete and there were no follow-up questions from Logius. That says enough about the quality.
Direct communication, a clear report and no surprises afterwards. The technical findings were also explained at management level. We’re happy to work together again next year.
During a quote conversation, with client consent, we can connect you with a comparable reference from your sector.
Frequently asked questions
Practical information.
Can we speak with a reference from our sector? +
Yes. During a quote conversation, with explicit client consent, we can connect you with a comparable reference. Get in touch via the quote page.
Is a data processing agreement available? +
Yes. For tests where personal data is in scope, a data processing agreement (GDPR-compliant) is signed as standard before the test begins.
Can you also serve larger organisations? +
Yes. Our team works for organisations of all sizes — from small SaaS startups to municipalities and healthcare providers. The approach is always tailored to the specific environment and scope.
Can the results be shared externally? +
The full technical report is confidential and intended for internal use and auditors under NDA. The management summary can be shared externally by arrangement — for example with clients or tendering parties.
Looking to commission a pentest?
We’re happy to discuss, with no obligation, whether a pentest fits your situation. Honest, and no pressure.
