10+ years of offensive testing, with the certifications and audit pedigree EU regulators expect — NIS2, DORA and ISO 27001.
10+ years offensive security
PASSI-qualified audit pedigree
Reporting in EN, NL & FR
OSCP · OSWE · OSWP · CRTO
Trusted by CTOs across the Netherlands and the EU
Hire senior security experts by the hour, day or project, no long-term commitments, just results.
Simulated real-world attacks surface the weaknesses that matter, before an attacker does.
Senior manual testing, not just AI scanners, hardens the controls automated tools miss.
Prioritised, board-ready reporting turns findings into security you can measure and show a supervisor.
The exact stack EU buyers ask for when scoping senior pentest or red-team work.
Every service runs standalone or bundled into a NIS2 programme. Fixed price, fixed scope, audit-ready output.
01
Internet-facing perimeter — exposed services, leaked secrets, weak edges. OWASP, OSSTMM and PTES methodology.
02
Assumed-breach scenario. Privilege escalation, lateral movement, Kerberos abuse, BloodHound, ACL chains, GPO hardening.
03
IAM, S3, networking, KMS, conditional access, PIM, MFA bypass, hybrid identity and M365 hardening. CIS benchmark plus exploitation.
04
OWASP Top 10 + API Top 10 — manual and AI-augmented. Authn/Authz, business logic, IDORs, race conditions, deserialization.
05
Manual secure-code review, SAST, dependency analysis (SCA) and secret scanning. For SDLC compliance under NIS2 Article 21(2)(e).
06
Multi-week and objective-based, initial access to data exfiltration, the full chain. Phishing pretexts, click-through and credential-harvest analysis.
07
Social engineering and on-site testing, tailgating, badge cloning, insider-threat scenarios. Surfaces the physical risks scans never see.
08
CISO-as-a-Service for strategy and audit readiness, plus SOC and incident-response support when something goes wrong.
Every engagement delivers executive and technical reporting in EN, NL or FR, written to be shown to a supervisor.
Article 21 testing evidence — perimeter, internal, application and SDLC controls, documented for supervisory review.
Threat-led penetration testing and ICT-risk evidence for financial-sector resilience requirements.
Technical testing that maps to Annex A controls and feeds straight into your ISMS audit trail.
No pitch, an honest read on scope, methodology and the right way of working for your environment.
Reporting in EN, NL & FR · fixed price, fixed scope
{{ t.heroLead }}
{{ t.stat1 }} {{ t.stat1sub }}
PASSI{{ t.stat2sub }}
{{ t.stat3 }} EN, NL & FR
OSCP · OSWE · OSWP · CRTO
{{ t.trustClaim }}
{{ t.whyLead }}
{{ t.why1d }}
{{ t.why2d }}
{{ t.why3d }}
{{ t.certLead }}
{{ t.compLead }}
{{ t.nis2d }}
{{ t.dorad }}
{{ t.isod }}