Commission a Penetration Test
Our team simulates realistic attacks on your systems to find vulnerabilities before attackers do. You receive a clear report with findings and concrete remediation steps.
What is a penetration test?
A penetration test (pentest) is a controlled attack on your systems by certified ethical hackers. Unlike an automated vulnerability scan, a pentest goes further: our team actively attempts to break in via logic flaws, business-layer vulnerabilities and attack chains that tools miss.
Our services
- Web application pentest — OWASP-based testing of your web application or customer portal
- API pentest — REST, GraphQL and SOAP APIs tested for authorization flaws and business logic
- External pentest — insight into your internet-facing risks via realistic attack scenarios
- Vulnerability scan — fast automated scan for known weaknesses
- Phishing simulation — test how employees respond to fake attacks
Our approach
- Scoping — together we determine what’s tested, which approach fits and what the objectives are
- Reconnaissance — passive and active information gathering about the target
- Vulnerability analysis — identification of potential weaknesses through manual work and targeted tools
- Exploitation — proof of abuse: we demonstrate how an attacker could exploit a vulnerability
- Reporting — a clear report with management summary, CVSS scores and concrete recommendations
- Debrief — we walk through the report and answer questions from your team
What’s in the report?
- Management summary — understandable for non-technical management too
- All findings with CVSS score, impact, reproduction steps and screenshots
- Concrete remediation advice per finding, sorted by priority
- Overview table for immediate prioritisation by your development or IT team
Certifications
Our team is certified via OSCP, OSWE, OSEP, eWPT, CEH and Pentest+. Hands-on certifications that prove we can actually break in. More on the certifications page.
FAQ
What’s the difference between a pentest and a vulnerability scan?
A vulnerability scan is automated and detects known weaknesses. A penetration test goes further: an ethical hacker actively attempts to break in and also finds logic and business-layer vulnerabilities that scanners miss. More on the page vulnerability scan vs. pentest.
How long does a penetration test take?
Depending on scope: a web application pentest usually takes 3 to 5 days. An API or external pentest 1 to 3 days. You always receive a fixed time and price quote in advance.
Do you work remote or on-site?
Most pentests are carried out fully remote. On-site is possible for internal network tests or when physical access is required.
Is a retest included?
A retest after remediation is optional and priced separately. We offer a targeted retest where only the found vulnerabilities are retested.
Is a penetration test mandatory for our organisation?
That depends on your sector. More information on the page is a penetration test mandatory?
Want to know more? Also see pentest pricing, hire a pentester, or request a quote directly.
Compliance & Sector-Specific Pentests
Does your organisation operate under specific regulations? We carry out pentests tailored to your industry’s requirements.
- DigiD Pentest & IT Security Assessment — mandatory for organisations with a DigiD connection
- ISO 27001 Pentest — support for certification
- NIS2 Pentest — technical assessment for NIS2-obligated organisations
- PCI DSS Pentest — mandatory test for payment environments
- Government Pentest — BIO-aligned for the public sector
- Healthcare Pentest — NEN 7510 and GDPR-focused
- SaaS Pentest — for software and platform companies
