Pen tests

NFIR holds the CCV quality seal of approval

Pentesting & security audits to test your digital resilience
NFIR beeldmerk kleur
NFIR beeldmerk kleur

Pen tests

NFIR holds the CCV quality seal of approval

Pentesting & security audits to test your digital resilience

Discover and address weaknesses in your digital defenses through a pentest. Our certified ethical hackers identify vulnerabilities and provide insight into the effectiveness of your security measures, as well as potential consequences if misused.

What is the importance of performing pentesting for your organization?

The main reasons to perform a pentest are:

  1. Identify vulnerabilities and risks:
    Get an overview of the vulnerabilities and risks present within your infrastructure and applications.
  2. Building trust:
    Customers, shareholders and other stakeholders expect their information to be secure. A pen test provides insight into your organization’s level of digital security.
  3. Comply with standards and legislation:
    Various standards and legislation such as the AVG, BIO, ENSIA and ISO, require appropriate security measures to be taken. A pentest helps you meet these requirements.
  4. Continuous security improvement:
    The results of the pen test can be used to improve and optimize your information security.
Home

Custom Pentesting

During an intake meeting, the exact scope for the pentest is determined and the environment to be examined is determined. In our intake meeting, we thoroughly go over your specific details, requirements, attack scenario and wishes. This allows us to create a customized proposal.

What we can pentest for you

It is possible to pentest the following environments. Infrastructure, Web Application, API, Mobile Application, Operational OT. If you have a different environment, we will be happy to discuss the possibilities together. It happens regularly that companies or organizations come to NFIR for “special” pen tests.

From pentesting to clear reporting

A pentest can be conducted from different perspectives, with the result depending (in part) on the chosen attack perspective. During an intake meeting, we will jointly determine the scope of the pen test and advise on how we can perform the most valuable pen test for your organization.

After we perform the pentest carefully and according to the applicable methodology and standard, you will receive a comprehensive report from us. In it you will find all the findings and clear solutions are provided to fix the vulnerabilities. Our reports are clear, complete and reproducible for your organization. We describe the standards used, the tests performed, the tooling applied and the measures recommended.

Request a sample pentest report here to gain insight into our method of reporting and the data we include in it.

Step 1: intake

During the intake, we discuss the scope components and attack scenarios of the pen test. An ethical hacker from NFIR is also present during the intake.
The intake is an important starting point because we would like to test all components within the scope of the pen test and identify all vulnerabilities. Based on the intake, we provide an hourly estimate and proposal.

Step 2: Proposal and agreements

After you receive the hour estimate and proposal, we will be happy to discuss your questions.
In consultation, we will find a suitable time to perform the pen test.

Step 3. implementation

During the pen test, we keep you informed about progress and vulnerabilities.
Critical vulnerabilities are reported immediately so that they can be resolved as soon as possible.

Step 4: Results

The vulnerabilities are documented in a clear and complete pen testing report. A standard part of our pentest services is to explain the findings following the delivered pentest report.
This explanation is greatly appreciated by our clients.

Step 5: Perfecting

Thanks to the clear insights, you are going to mitigate the vulnerabilities.
If required, we can arrange for a retest after the vulnerabilities have been mitigated. Based on this retest, you will receive a new pen test report and have confirmation that the vulnerabilities have actually been fixed

Let us assess your risks!

Find out how safe you really are and contact us today.

We offer different attack scenarios

Black box pen testing hacker organization applications security information

Black Box pentest

In a Black Box attack scenario, minimal information is provided in advance by the client. Ethical hackers will operate as "outsiders" without inside information. Pentesters use various techniques, including Open Source Intelligence (OSINT) to discover vulnerabilities.

Grey box pen testing risk hackers automated network penetration test the netherlands

Grey Box Pentest

A Grey Box attack scenario sits between a Black and White box. There is "limited" sharing of information used to investigate an environment. The ethical hackers will use a user account to examine the infrastructure or application.

white box pentesting ethical hardware vulnerability pentester security audit computer systems

White Box Pentest

In a White Box attack scenario (also known as a Crystal box), all information is provided in advance to target vulnerabilities. Consider the information that is also requested in Grey Box pentesting. In addition, source code, log files and server access are used. In addition, the ability to set up your own test environment can be used.

Certified and quality-focused Ethical Hackers

Our skilled and professional ethical hackers have extensive experience, creativity and up-to-date professional knowledge. They have completed relevant training and are certified, such as OSCPOSWPOSWE, OSEP, CPTSCBBH, and eWPT. In addition, NFIR holds a CCV seal of approval for pentesting.

CyberSecurity Event Zwolle

NFIR uses reliable pentesting services, certified with the CCV Pentesting Seal of Approval. We are your Cybersecurity partner if you are looking for a down-to-earth Dutch Cybersecurity company that has years of experience in pentesting. Our certified ethical hackers identify vulnerabilities and provide concrete and actionable insights about the effectiveness of your security measures. Contact us today to put your cybersecurity under the microscope as well.

Contact us for a professional pentest

Contact us to schedule your pentest intake. Request a sample pentest report here to gain insight into how we report and the data we include in it.

Perform pentest?

Strengthen your digital resilience and gain customer trust with our thorough pen testing.
Pentest

A vulnerability scan uses automated scans to discover known vulnerabilities. These vulnerabilities are then reported. It is an important first step in understanding potential weaknesses within a system.
A pentest goes one step further. During a pentest, not only are vulnerabilities identified, but they are actually exploited. This demonstrates what the actual consequence may be to a system or environment when compromised. The ethical hacker will use his experience and creativity to identify all the weaknesses of an environment, giving the organization a more realistic picture of the risks they face.

Penetration test or vulnerability assessment? – Have a Pentest Performed – Contact NFIR Now

Depending on the size of the job, a careful assessment is made as to whether multiple people should be put on a pentest to reduce the length of the job. The duration of a pentest can vary depending on the environment being tested and the complexity of the attack scenarios being used. Generally, a pentest covers a period of 2 to 4 weeks. This period includes not only the execution of the test itself, but also the preparation, analysis and explanation of the final report.

A pentest (penetration test) is necessary because companies are often unaware of vulnerabilities in their network and systems. It is a controlled and authorized attempt to evaluate security through a simulated attack. The main reasons for a pentest include vulnerability identification, risk management, regulatory compliance, evaluation of new applications and changes, protection of customer data, and building trust with customers and stakeholders. Conducting regular pentests is essential to improve security and prepare for potential attacks.

  • For example, a pen test is useful to:
    Assess your current situation for vulnerabilities.
  • Detect vulnerabilities before the release of new applications.
  • Check weaknesses after changes to infrastructure or applications.
  • Comply with corporate policies, standards and/or legislation that require periodic security assessments.
  • Test your Cybersecurity maturity against the detection methods you have implemented.

When performing a pentest, various international standards and methodologies are used to discover and classify vulnerabilities.

Some of the key standards applicable to the assignment include:

By using these standards, a pentest can be performed in a structured and thorough manner, and the results can be reported in a clear and comparable way.

Our pentesters have a large amount of experience, a lot of creativity and up-to-date expertise. The NFIR pentesters have followed relevant training courses and obtained certifications such as OSCP. In addition, they have all received chief of police approval and signed confidentiality agreements.

A Black Box pentest means that no information about the environment is shared with the pen testers beforehand. With a pentest based on the White Box principle, all information about the environment is shared in advance. If you are having a pentest performed for the first time and want to get an overall picture of your security, it is useful to have a Black Box pen test performed.

  • OWASP WSTG

The Web Security Testing Guide (WSTG) project is the premier cybersecurity testing resource for Web application developers and security professionals. The WSTG is a comprehensive guide to testing the security of Web applications and Web services. Created through the combined efforts of cybersecurity professionals and dedicated volunteers, the WSTG provides a framework of best practices used by penetration testers and organizations around the world.

  • OWASP MASTG

The OWASP Mobile Application Security Testing guide is a mobile app security standard and comprehensive testing guide that covers the processes, techniques and tools used during a mobile app security test, as well as a comprehensive set of test cases that allow testers to deliver consistent and complete results.

The Penetration Testing Execution Standard (PTES) consists of several main components. These cover everything about a penetration test, namely:

  1. The initial communication and reasoning behind a pentest;
  2. The information gathering and threat modelling phases, where testers work behind the scenes to gain a better understanding of the tested organisation;
  3. Vulnerability assessment, exploitation and post-exploitation, which addresses the technical security expertise of the testers and combines it with the business insight of the assignment;
  4. Reporting, which captures the entire process in a way that makes sense to the customer and provides them with the most value.

The Common Vulnerability Scoring System (CVSS) standard provides an open framework for disclosing the characteristics and consequences of software and hardware security vulnerabilities. The quantitative model is designed to ensure consistent and accurate measurement while allowing users to see the underlying vulnerability characteristics used to generate the scores.

High quality pen testing

Certified and quality-oriented pentesters

Pentests are essential to test the technical resilience and effective operation of security. Our pentesters focus on identifying vulnerabilities in systems by deploying various attack techniques. Our skilled and professional pen testers have extensive experience, creativity and up-to-date professional knowledge. The pentesters have completed various relevant training courses and hold the following certifications, among others, OSCP, OSWP, OSWE, OSEP, CPTS, CBBH, and eWPT.

Pentesting and the CCV seal of approval:

  • This quality mark, based on NEN-EN-ISO/IEC standards 17021 and 17065, gives customers the guarantee that the execution of a pen testing assignment by NFIR is carried out in a professional and high-quality manner.
  • NFIR possesses since 07-01-2022 the CCV quality mark for Pentesting. logo ccv nl, Center for Crime Prevention and Security, pentest seals of approval.

I want to pentest my environment(s)!

Once you fill out this form, we will contact you immediately to inform you of the possibilities. We schedule a no-obligation intake with a Technical Lead to coordinate scope components and attack scenarios.

Do you have any questions in the interim? If so, please contact us by phone at the general NFIR phone number: 088 313 0205

A man in a blue shirt shakes hands with another person in front of a sign that reads "NO NONSENSE CYBER SECURITY EXPERTS," emphasizing expertise in pen testing and security monitoring.

SECURITY INCIDENT AT YOUR ORGANIZATION?

The next 30 minutes are crucial!

The first 30 minutes after a cyber security incident are crucial because a quick and adequate response can limit the damage. In addition, further spread of the attack can be prevented and essential evidence can be secured for further investigation.

Our Computer Emergency Response Team (CERT) is available 24/7 to support businesses and organizations during IT security incidents.

SECURITY INCIDENT AT YOUR ORGANIZATION?

The next 30 minutes are crucial!

The first 30 minutes after a cyber security incident are crucial because a quick and adequate response can limit the damage. In addition, further spread of the attack can be prevented and essential evidence can be secured for further investigation.

Our Computer Emergency Response Team (CERT) is available 24/7 to support businesses and organizations during IT security incidents.

Op basis van meer dan 600 succesvol uitgevoerde pentesten.

Top 10 meest voorkomende cyber kwetsbaarheden bij Nederlandse Gemeenten

Download gratis whitepaper
De besproken kwetsbaarheden worden wereldwijd misbruikt, zo ook bij de Nederlandse gemeenten. Het doel van deze paper is gemeenten inzicht te geven in huidige dreigingen en hen te helpen bij het verbeteren van  beveiligingsmaatregelen. NFIR streeft naar transparantie om de weerbaarheid van gemeenten te verhogen en cyberaanvallen proactief tegen te gaan.

* geen registratie nodig, direct downloaden

Voer hier de inhoud in. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Pen tests

Penetration test?

Pen tests

Penetration test?

Pen tests

Penetration test?

Wat is MDR?

Managed Detection and Response (MDR) is een gespecialiseerde cybersecuritydienst die organisaties proactief beschermt tegen cyberdreigingen door een combinatie van geavanceerde technologie en menselijke expertise. Deze dienst biedt 24/7 monitoring, diepgaande analyse en proactieve dreigingsopsporing, met als doel het snel detecteren, onderzoeken en actief reageren op incidenten om de impact te minimaliseren en datalekken of ransomware-aanvallen te voorkomen, vanuit de aanname dat inbreuken onvermijdelijk zijn.

Wat is Security Monitoring

Security Monitoring is een essentieel onderdeel van Managed Detection and Response (MDR) en omvat de continue, 24/7 bewaking van de IT-omgeving van een organisatie, inclusief netwerken, systemen, applicaties, endpoints en cloudomgevingen. Het maakt gebruik van geavanceerde technologieën zoals AI en machine learning om loggegevens te filteren en te analyseren, verdachte activiteiten te detecteren en afwijkingen te identificeren.

Deze geautomatiseerde detecties worden vervolgens gevalideerd en geprioriteerd door menselijke beveiligingsspecialisten, die context en expertise toevoegen om vals-positieven te verminderen en echte dreigingen te onderscheiden. Het doel is om real-time inzicht te bieden in de beveiligingsstatus, kwetsbaarheden te identificeren en een snelle respons op incidenten mogelijk te maken, wat cruciaal is voor naleving van regelgeving zoals NIS2 en DORA.

Pentesten

Penetratietest laten uitvoeren?

 

Pentesten

Penetratietest laten uitvoeren?

 

Pen tests

Penetration test?

Pen tests

Penetration test?

Pen tests

Penetration test?

Pentesten

Penetratietest laten uitvoeren?

 

What is MDR?

Managed Detection and Response (MDR) is a specialized cybersecurity service that proactively protects organizations from cyber threats through a combination of advanced technology and human expertise. This service provides 24/7 monitoring, in-depth analysis and proactive threat detection, with the goal of quickly detecting, investigating and actively responding to incidents to minimize impact and prevent data breaches or ransomware attacks, based on the assumption that breaches are inevitable.

What is Security Monitoring

Security Monitoring is an essential component of Managed Detection and Response (MDR) and involves the continuous, 24/7 monitoring of an organization's IT environment, including networks, systems, applications, endpoints and cloud environments. It uses advanced technologies such as AI and machine learning to filter and analyze log data, detect suspicious activity and identify anomalies.

These automated detections are then validated and prioritized by human security specialists, who add context and expertise to reduce false positives and distinguish true threats. The goal is to provide real-time visibility into security status, identify vulnerabilities and enable rapid incident response, which is critical for regulatory compliance such as NIS2 and DORA.

Secure/evidence seizure - Secure phones, laptops & devices

NFIR offers support in the execution of digital evidence seizures. Depending on the situation, we can assist you directly with this based on our license as a Private Investigation Agency, granted by the Ministry of Justice and Security, or in cooperation with a bailiff.

We ensure that a snapshot is taken of relevant assets so that they can be examined at a later date if necessary. A non-exhaustive list of devices where we provide support includes:

  • Phones
  • Laptops
  • Tablets
  • NAS systems
  • Cameras
  • Cloud storage (Google Drive, Dropbox, Microsoft 365, OneDrive, SharePoint, etc.)
  • And many more, as long as it contains a 0 or a 1

In addition to securing and preserving potential evidence, NFIR also provides support in analyzing it. We can investigate both technical and tactical issues.

Examples:

  • Technical issue: "Was the device hacked at the time of the situation?"
  • Tactical issue: "Is there evidence to suggest possible forgery of these documents?"

Are you in need of these or any of our other services? If so, please contact us here. We will make sure you get a concrete answer to your questions as soon as possible.

What is surety or evidence seizure?

Evidence seizures and sureties are legal measures used to secure evidence or property in legal proceedings.

Evidence seizure is a procedure in which a party, often with court approval, seizes documents, digital data or other evidence. This is done to prevent such information from being lost, destroyed or otherwise inaccessible. Evidence seizures are often used in civil cases, such as intellectual property disputes or fraud investigations.

Securing has a broader application and can refer to securing goods, property or financial resources to protect rights or to fulfill a legal obligation. This can include criminal, civil or administrative law contexts. Consider seizing assets in bankruptcies or blocking bank accounts in cases of suspected money laundering.

Both measures aim to prevent important documents or resources from disappearing before a judge can rule on a case.

Pentest consultation

Pentesten

Penetratietest laten uitvoeren?

 

Pentesten

Penetratietest laten uitvoeren?

 

Pentesten

Penetratietest laten uitvoeren?

 

Pentesten

Penetratietest laten uitvoeren?

 

Pen tests

Penetration test?

Voer hier de inhoud in. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Voer hier de inhoud in. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Has my company been hacked (Compromise assessment)?

A complete check-up of your digital environment!

The crown jewels of many companies today are digital. That no third parties are secretly accessing that important database? Or have been watching that one server for ages? NFIR helps with a compromise assessment!

During a compromise assessment, NFIR's experts take a close look at all or part of your network, depending on your requirements. We will thoroughly investigate whether there is or has been intrusion by unauthorized parties on your systems. We do this using Threat Intelligence reports and already known Indicators of Compromise; indicators that indicate that something may be amiss.

This is different from a pen test, which can be used preventively to look for security vulnerabilities. In a compromise assessment, NFIR looks for actual misuse of these potential leaks.

If you have doubts about the integrity of your network, perhaps because of a previous incident or hard to pinpoint alerts from your monitoring systems, NFIR is here for you!

Pentest consult

zekerstellen/bewijsbeslag - Veiligstellen telefoons, laptops & apparaten

NFIR biedt ondersteuning bij het uitvoeren van digitaal bewijsbeslag. Afhankelijk van de situatie kunnen wij u hier direct bij assisteren op basis van onze vergunning als Particulier Onderzoeksbureau, verleend door het Ministerie van Justitie en Veiligheid, of in samenwerking met een deurwaarder.

Wij zorgen ervoor dat een momentopname wordt gemaakt van relevante goederen, zodat deze indien nodig op een later moment onderzocht kunnen worden. Een niet-uitputtende lijst van apparaten waarbij wij ondersteuning bieden, omvat:

  • Telefoons
  • Laptops
  • Tablets
  • NAS-systemen
  • Camera’s
  • Cloudopslag (Google Drive, Dropbox, Microsoft 365, OneDrive, SharePoint, etc.)
  • En nog veel meer, zolang het maar een 0 of een 1 bevat

Naast het veiligstellen en bewaren van mogelijk bewijsmateriaal, biedt NFIR ook ondersteuning bij het analyseren ervan. Wij kunnen zowel technische als tactische vraagstukken onderzoeken.

Voorbeelden:

  • Technisch vraagstuk: “Was het apparaat gehackt ten tijde van de situatie?”
  • Tactisch vraagstuk: “Is er bewijs dat wijst op mogelijke vervalsing van deze documenten?”

Heeft u behoefte aan deze of een van onze andere diensten? Neem dan hier contact met ons op. Wij zorgen ervoor dat u zo snel mogelijk een concreet antwoord krijgt op uw vragen.

Wat is zekerstellen of bewijsbeslag?

Bewijsbeslag en zekerstellen zijn juridische maatregelen die worden gebruikt om bewijs of eigendommen veilig te stellen in juridische procedures.

Bewijsbeslag is een procedure waarbij een partij, vaak met toestemming van de rechter, beslag legt op documenten, digitale gegevens of andere bewijsmiddelen. Dit wordt gedaan om te voorkomen dat deze informatie verloren gaat, vernietigd wordt of anderszins onbereikbaar wordt. Bewijsbeslag wordt vaak ingezet in civiele zaken, bijvoorbeeld bij geschillen over intellectueel eigendom of fraudeonderzoeken.

Zekerstellen heeft een bredere toepassing en kan slaan op het veiligstellen van goederen, eigendommen of financiële middelen ter bescherming van rechten of ter uitvoering van een juridische verplichting. Dit kan onder andere gebeuren in strafrechtelijke, civielrechtelijke of bestuursrechtelijke contexten. Denk aan het in beslag nemen van activa bij faillissementen of het blokkeren van bankrekeningen bij vermoedens van witwassen.

Beide maatregelen hebben als doel te voorkomen dat belangrijke stukken of middelen verdwijnen voordat een rechter zich over een zaak kan uitspreken.

Is mijn bedrijf gehackt? (Compromise assessment)

Een volledige check-up van uw digitale omgeving!

De kroonjuwelen van veel bedrijven zijn tegenwoordig digitaal. Dat er geen derde partijen stiekem toegang hebben tot die belangrijke database? Of al tijden mee zitten te kijken op die ene server? NFIR helpt met een compromise assessment!

Tijdens een compromise assessment nemen de experts van NFIR uw netwerk geheel of gedeeltelijk, afhankelijk van uw wens, onder de loep nemen. We gaan goed onderzoeken of er op uw systemen sprake is of is geweest van intrusie door ongeautoriseerde partijen. Dit doen wij aan de hand van Threat Intelligence rapporten en reeds bekende Indicators of Compromise; indicatoren die erop wijzen dat er mogelijk iets niet in de haak is.

Dit is anders dan een pentest, welke preventief kan worden ingezet om te zoeken naar beveiligingslekken. Bij een compromise assessment gaat NFIR op zoek naar daadwerkelijk misbruik van deze mogelijke lekken.

Als u twijfelt aan de integriteit van uw netwerk, misschien vanwege een eerder incident of vanwege moeilijk te duiden waarschuwingen van uw monitoring systemen, staat NFIR voor u klaar!

SECURITY INCIDENT AT YOUR ORGANIZATION?

The next 30 minutes are crucial!

The first 30 minutes after a cyber security incident are crucial because a quick and adequate response can limit the damage. In addition, further spread of the attack can be prevented and essential evidence can be secured for further investigation.

Our Computer Emergency Response Team (CERT) is available 24/7 to support businesses and organizations during IT security incidents.