✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

Pentest for Government and the Public Sector

Government organisations process sensitive personal data and are required to comply with the Baseline Information Security for Dutch Government (BIO). A periodic penetration test is a core measure within this framework.

What is the BIO and what does it require?

The BIO is the mandatory information security framework for all levels of Dutch government: central government, provinces, municipalities and water boards. The BIO is based on ISO 27001 and requires, among other things:

  • Regular technical vulnerability testing (BIO 12.6)
  • Penetration tests on critical systems
  • Specific tests for DigiD connections (LOGIUS requirement)
  • Logging and monitoring of security events

Our services for the public sector

Experience with government environments

Government environments require confidentiality, specific compliance documentation and a test methodology aligned with BIO and NCSC guidelines. MonkeysICT works in accordance with these frameworks and delivers reports usable by your CISO, auditor and regulator.

FAQ

Does a municipality need to run a pentest annually?

The BIO requires regular vulnerability testing. For systems with a DigiD connection, an annual obligation applies from LOGIUS. For other systems, annual testing is the practical standard.

Do you work with a data processing agreement?

Yes. For government assignments we provide a data processing agreement as standard, in accordance with the GDPR and the requirements of the Netherlands Enterprise Agency.

Can you test remotely so we don’t have to open up our systems?

Yes, we carry out most pentests fully remote. For internal network tests, we set up VPN access to a managed test environment, minimally invasive to your infrastructure.

Also see: DigiD pentest | ISO 27001 | NIS2 | request a quote

Scroll to Top