Approach and methodology

From assessment question to useful insight.

A penetration test starts with what you want to protect. We investigate realistic attack paths, substantiate what we find and explain which next steps matter for your organisation.

How we work

How our specialists carry out the assessment.

We start with your reason for the assessment, the most important systems and the processes that depend on them. Together, we determine which questions the assessment should answer and from which perspective we test. This may involve little prior knowledge, agreed access or an assumed breach.

Our researchers combine a structured approach with an attacker's perspective. Tools help gather information. Our people verify findings, examine connections and assess what a vulnerability could really mean in your environment.

From intake to discussion

How the assessment proceeds.

1

Defining the objective and scope

We discuss your reason for the assessment, assessment questions and schedule. We document which systems and scenarios are included, what access is needed and which conditions apply. Where relevant, we refine the choices with a threat analysis.

2

Preparing together

You receive a dedicated secure project environment. We agree on contacts, testing times, access and communication. Before active testing, we check the targets and arrangements so that everyone knows what will happen.

3

Controlled testing

We map the attack surface and test potential vulnerabilities. Findings are manually validated. Where agreed and appropriate, we investigate further access or connected attack paths, always within the agreed scope and operational conditions.

4

Analysis and reporting

We connect technical findings to the consequences for your organisation. The report contains evidence, risks, priorities and recommendations. A second colleague reviews the report internally before we deliver it.

5

Discussion and further help

During the joint discussion, we explain the outcomes and answer questions. You know which findings need attention and which measures help. A retest to check implemented improvements is agreed separately.

Assessment and reporting in accordance with MIAUW.

We work in accordance with the Methodiek voor Informatiebeveiligingsonderzoek met Auditwaarde (Methodology for Information Security Assessments with Audit Value). The assessment approach and reporting show what was examined, how conclusions were reached and what recommendations are based on. This allows technical teams and management to determine next steps from the same evidence.

Depending on the assessment, we use additional testing frameworks, such as OWASP WSTG, NIST SP 800-115 and MITRE ATT&CK. The chosen frameworks support the assessment question and are explained in the report.

Your own secure data room.

Every customer receives a dedicated project environment in Tresorit. We use it to share the scope, required documents, project updates and reports. This keeps the information and coordination around the assessment organised in one secure place.

We agree who receives access and how we exchange sensitive information. During the project, you have direct contact with the specialists involved.

What you receive afterwards.

Insight for management

An understandable summary of the resilience assessed, the main risks and what they mean for the organisation.

Evidence for technical teams

Validated findings with evidence, relevant context and practical recommendations. Additional technical appendices are made available separately where needed.

An order for improvement

We set priorities based on what an attacker could do with a finding, the consequences and its connections with other findings. This allows you to make targeted improvements.

Our understanding guarantee means we keep explaining the findings until the IT and security leads involved understand what was found and which next steps follow.

How do we handle assessment data?

We process data for the agreed assessment and limit testing activities to the defined scope. We document arrangements for access, confidentiality and retention periods within the project. Keep your own copy of the report securely if you need it for longer, for example for an audit.

Discuss your penetration test.

Tell us what you want assessed. Together, we define the assessment question, scope and next step.