✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

References & Cases

What our clients
say — and what we found.

Confidentiality is a core value. All cases are anonymised and approved for publication. The findings and approach are authentic.

50+
Pentests performed
6
Recognised certifications
100%
Manual testing
<5
Business-day report

Completed assignments

Three cases — three sectors.

01
SaaS · Web application pentest · Grey box

Critical authorisation flaw in B2B platform — customer data from 80 organisations accessible

Situatie

A growing SaaS company with a B2B project-management platform for around 80 business customers requested a grey box web application pentest, including API, ahead of an enterprise tender.

Bevinding

A Broken Object Level Authorization (BOLA) vulnerability in the API made it possible, as a logged-in user, to retrieve data from other organisations by modifying the object ID in the request. All customer data was accessible without additional privileges.

Resultaat
✓ Fixed within 48 hours

Vulnerability patched, authorisation checks implemented on all API endpoints. Retest confirmed correct remediation. Tender completed successfully.

02
Government · DigiD assessment · NIBAD compliant

DigiD ICT security assessment for a municipality — Logius deadline met

Situatie

A Dutch municipality with a DigiD-integrated citizen portal needed to submit an annual ICT security assessment to Logius under the NIBAD standard, with a tight submission deadline.

Bevinding

A session-handling misconfiguration left expired session tokens valid after logout. In addition, adequate logging of authentication attempts was missing — a direct compliance shortfall for Logius.

Resultaat
✓ No follow-up questions from Logius

Both findings resolved before the deadline. Report submitted fully compliant with NIBAD. The municipality subsequently signed an annual testing agreement.

03
Healthcare · NEN 7510 · Combined vulnerability scan + pentest

Healthcare provider with EHR integration — insufficient segmentation and outdated software

Situatie

A specialised healthcare provider with around 200 staff and an EHR integration commissioned a combined vulnerability scan and grey box pentest in preparation for NEN 7510 certification.

Bevinding

Outdated software versions on internal servers, unsecured admin interfaces reachable via the internal network, and insufficient segmentation between the care environment and general IT infrastructure — together a high risk of unauthorised access to patient data.

Resultaat
✓ NEN 7510 process started

A quarterly priority plan was drawn up. After three months of remediation a retest was performed. The report was used as the basis for the NEN 7510 certification process.

Wat opdrachtgevers zeggen

In their own words.

“

Our team hadn’t expected a critical flaw to be found so quickly. The report was clear, even for our non-technical management. The collaboration was direct and pleasant — no hassle.

CTO, SaaS-bedrijf
B2B project-management platform · anonymised
“

We had a tight deadline for Logius. MonkeysICT delivered on time, the report was complete and there were no follow-up questions from Logius. That says enough about the quality.

Data Protection Officer
Municipality · anonymised on request
“

Direct communication, a clear report and no surprises afterwards. The technical findings were also explained at management level. We’re happy to work together again next year.

IT-manager
Mid-sized municipality · anonymised on request
Would you like to speak with a reference?

During a quote conversation, with client consent, we can connect you with a comparable reference from your sector.

Schedule a call →

Frequently asked questions

Practical information.

Can we speak with a reference from our sector? +

Yes. During a quote conversation, with explicit client consent, we can connect you with a comparable reference. Get in touch via the quote page.

Is a data processing agreement available? +

Yes. For tests where personal data is in scope, a data processing agreement (GDPR-compliant) is signed as standard before the test begins.

Can you also serve larger organisations? +

Yes. Our team works for organisations of all sizes — from small SaaS startups to municipalities and healthcare providers. The approach is always tailored to the specific environment and scope.

Can the results be shared externally? +

The full technical report is confidential and intended for internal use and auditors under NDA. The management summary can be shared externally by arrangement — for example with clients or tendering parties.

Looking to commission a pentest?

We’re happy to discuss, with no obligation, whether a pentest fits your situation. Honest, and no pressure.

Scroll to Top