Have a pentest carried out by experienced specialists? Choose SECWATCH
How does SECWATCH carry out a pentest?
Carrying out a pentest starts with a clear objective. During a short intake, we discuss which systems, applications or internet-accessible services need to be examined.
Our certified ethical hackers then carry out an in-depth test tailored to your organisation.
You receive a practical report with clear priorities, concrete recommendations and direct explanations from the specialists who carried out the test.
Want to know more about having a pentest carried out? Read our article: Having a pentest carried out: why technology is rarely the real problem.
Do not wait! This type of pentest is highly specialised: a maximum of 10 per month!
More than 1,500 pentests completed
We have been carrying out specialist research into networks and software since 2005, performing more than 100 pentests a year. We work for hundreds of organisations in every sector, from government to business. No automated scan reports, but research by our specialists who show you where you face real risks and what needs attention first.
With our understanding guarantee, our pentesters keep going until every person responsible for IT or security knows 100% what we have identified and what steps are needed to resolve it
Do not wait any longer. Because of our specific approach, we have capacity for a maximum of 10 pentests.
Healthcare institution
Other patients’ appointment records were accessible, unnoticed by three previous pentests
During a pentest for a healthcare organisation, we found a critical vulnerability with an enormous impact: unauthorised users could view patients’ appointment records. A nightmare for any healthcare institution.
The client’s developer said this was impossible: ‘That does not seem right. Are you sure you saw that correctly?’ We were 95% convinced that this was a high-impact issue. By working like cybercriminals, we managed to reproduce the problem. The developer was grateful for our persistence. The institution immediately took action and resolved the problem.
“The price is clear in advance and does not change, even if the test reveals that further investigation is needed.”
Matthijs Brunsting, Software Development Team Leader at Solviteers
“SECWATCH never makes a fuss if something changes in the scope. Even if a retest adds a little more. No surprises afterwards.”
Anonymous, director of a cloud document system with several hundred thousand personnel files
“During a pentest, we have direct contact with the SECWATCH experts carrying it out. Those short lines of communication make working together quick and effective, without noise or detours.”
Anonymous, risk manager at a large insurance company
The Meticulous Pentest
One test. Countless ways it helps you better protect your organisation. A preview of the results of our pentest:
-
Are you a CISO or IT manager who already has a great deal of good internal security in place? Then it is particularly important to see how ethical hackers, by using manual investigation and analogue thinking like a real hacker, can still find gaps and vulnerabilities in your online security.
-
You can only establish where you are truly vulnerable, and how to protect yourself, by thinking specifically like a hacker.
-
Because we provide meticulous, tailored work, you never buy too much or too little, but precisely what you need. No unnecessary costs: we do not sell you anything you do not need.
-
Our ‘data detectives’ do not simply ignore vulnerabilities because a scanner has labelled them ‘low risk’. We know that the impact of a low-risk vulnerability can be very high: this way of working is essential for identifying costly threats and data breaches.
-
Through our thorough preparation phase, using both passive and active enumeration, our ethical hackers identify deeper, specific vulnerabilities that could seriously harm your organisation’s cybersecurity.
-
Our testers regularly uncover vulnerabilities that were NOT identified in previous pentests and have an enormous impact on companies’ internal cybersecurity.
-
Did you know that we work at the highest level with the Dutch government and cybersecurity specialists? This gives us first-hand access to use cases, knowledge and test results.
-
Why are our specialist pentesters a breath of fresh air for your developers? Because they can improve the quality of their software.
-
Because our pentesters think like real hackers, they find attack methods that cybercriminals can also use and uncover information that generic scanners miss.
-
100% of our ethical hackers hold at least the CEH certification. Indeed: at least. And that is before we even mention ECSA/LPT, OSCP, GWAPT, GXPN, GAWN and OSWE.
-
Please note: if you have a complex technological setup, the strength of your security depends on the scope. That is why our specialists examine every possible route, and nothing is ever ‘out of scope’ if a cybercriminal would not consider it out of scope either.
-
With our understanding guarantee, we keep going until every person responsible for IT or security knows 100% what we have identified and what steps are needed to resolve it.
Ready for the Meticulous Pentest?
Do not wait: in four to six weeks, you could have a specific security report with specific security measures for your specific business and sector.
1
Scoping
After your request, we schedule a Clarity Call to clarify the scope and your requirements. What will we test? What are the dependencies? When can we start?
2
Preparation
We arrange the authorisation and indemnity, agree the schedule and duration, and schedule the debrief. From that point on, we stay in close contact about progress.
3
Pentest
Our specialists get to work and look at your technology, systems, software and anything else that interests a cybercriminal, through a hacker’s eyes.
4
Investigation
We analyse and classify everything we find. We assess all the data against your specific challenges and assets. This is the data detective work.
5
Debrief
You receive a clear report with a highly relevant overview. Our understanding guarantee comes into effect: our specialists create clarity down to the very last letter.
What fits your situation?
Choose what you want assessed.
External network
Which systems are accessible from the internet and where could an attacker gain entry?
Internal network
Which permissions and weaknesses allow further steps within your network?
Web application & API
Which technical vulnerabilities and flaws in your web application or API could an attacker use?
Cloud Security Assessment
Do accounts, permissions and settings match the access you intend to grant?
Detection & Response Validation
Are attack activities detected, investigated and followed up properly?
Assumed breach test
What could an attacker reach after an assumed breach? We test a targeted threat scenario.
Depth and clear decisions
We continue to help after the report.
You receive a report with substantiated findings, priorities and remediation advice. We discuss the results with your team and help you determine which next steps are needed.
- An evidence-based picture of the environment tested.
- Technical explanations and remediation priorities.
- An explanation your team and management can act on.
Black box, grey box or white box? This describes how much information and access we receive in advance. Together, we choose what fits your question.
You can also come to us with questions afterwards. Our understanding guarantee means we keep explaining the findings and advice until it is clear what we found, what it means for your organisation and how you can act on it.

A different assessment question?
People, processes and attack scenarios matter too.
And between penetration tests?
Your environment keeps changing. With Exposure Control, we track changes in your external systems and web applications. Our specialists assess the signals and explain which findings need attention. Planned or mandatory penetration tests remain in place.
Questions about commissioning a penetration test.
Are there risks involved in a penetration test?
A penetration test can affect your systems. We agree the scope, testing times and permitted activities in advance to reduce the likelihood of disruption.
Can I commission a penetration test if my IT is outsourced?
Yes. We agree the scope, required permission, access and schedule with you and your IT partner.
Can I share the report with external stakeholders?
Yes. The report contains explanations for management and technical teams. Share sensitive assessment information only with the parties involved, through a secure channel.
Stop generic pentests. Start specific pentests.
Discuss your situation with a security specialist
The form is currently unavailable. Use our general contact form or call 036 5367 573.
We use your details to handle your enquiry. Read our privacy policy.