{"id":3359,"date":"2019-10-21T12:12:02","date_gmt":"2019-10-21T10:12:02","guid":{"rendered":"https:\/\/wordpress-348070-1639297.cloudwaysapps.com\/pen-tests-you-need-to-know-about-this\/"},"modified":"2024-08-19T15:35:55","modified_gmt":"2024-08-19T13:35:55","slug":"pen-tests-you-need-to-know-about-this","status":"publish","type":"page","link":"https:\/\/www.cyber-security-online.nl\/en\/pen-tests-you-need-to-know-about-this\/","title":{"rendered":"Pentesting and Penetration Testing: <br>Everything you need to know about pen testing."},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"3359\" class=\"elementor elementor-3359 elementor-1261\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-146198d e-flex e-con-boxed e-con e-parent\" data-id=\"146198d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-29630d6 e-con-full e-flex e-con e-child\" data-id=\"29630d6\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-303e647 elementor-widget elementor-widget-heading\" data-id=\"303e647\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Pentesting and Penetration Testing: <br>Everything you need to know about pen testing.<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6dbdb6a elementor-widget elementor-widget-text-editor\" data-id=\"6dbdb6a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>It is becoming increasingly important for companies and organizations to have <a href=\"https:\/\/www.cyber-security-online.nl\/en\/pentesten-security-audits-to-test-your-digital-resilience-2\/\" target=\"_blank\" rel=\"noopener\">pen testing<\/a> performed on their (web) application, website, IT infrastructure, interfaces (APIs) and\/or mobile apps. A penetration test (also known as a pen test) can reveal where the risks and vulnerabilities of the systems under investigation lie. In addition, improvements can be targeted to strengthen security to mitigate risks and vulnerabilities.<\/strong><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5214ac2 e-con-full e-flex e-con e-child\" data-id=\"5214ac2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-c0248bf e-con-full e-flex e-con e-child\" data-id=\"c0248bf\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-90fe3a0 elementor-widget elementor-widget-heading\" data-id=\"90fe3a0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What exactly is a pen test?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7188e84 elementor-widget elementor-widget-text-editor\" data-id=\"7188e84\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>A pen test, or penetration test or penetration testing, is an important element within IT and organizational security. It is basically an authorized simulated attack on a computer system, carried out to evaluate vulnerabilities. Pen testing often involves the use of a <i>penetration testing toolkit<\/i>. This toolkit contains various tools and techniques that help expose any weaknesses. The user, in this case the organization, uses the results of the pen test to get a better picture of the current security status.<br \/>\nThus, an effective security audit can be conducted to target security gaps.  That&#8217;s why pen tests are so important; <b>they provide insight into vulnerabilities that might otherwise be overlooked.<\/b><\/p>\n<p>A pen test at NFIR is performed by certified ethical hackers who examine your systems for vulnerabilities. The ethical hackers try to uncover weaknesses in systems in various ways. Through a combination of automated tooling and creativity, ethical hackers attempt to gain unauthorized access to information and\/or systems. A pen test is <b>always<\/b> commissioned and authorized by the owners of the systems being tested. In fact, if there is no indemnification statement then there is computer infringement. After a pen test is performed, the findings are shared with the client through a report. This report describes in detail the vulnerabilities found, determines the scores using the CVSS (Common Vulnerability Scoring System) and provides advice on how to fix the vulnerabilities. It is recommended that a pen test be performed periodically, as <a href=\"https:\/\/www.cyber-security-online.nl\/en\/7-important-questions-about-pen-testing\/\" target=\"_blank\" rel=\"noopener\">a pen test is a snapshot in time<\/a> and environments are often subject to change.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d06c084 elementor-widget elementor-widget-heading\" data-id=\"d06c084\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Curious about a sample report from a Pentest?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6bfcff1 elementor-align-center elementor-widget elementor-widget-button\" data-id=\"6bfcff1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cyber-security-online.nl\/en\/pentesten-security-audits-to-test-your-digital-resilience-2\/request-pentest-report\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Sample reporting Pentest<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9307a2e e-con-full e-flex e-con e-child\" data-id=\"9307a2e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-77cdcf2 elementor-toc--minimized-on-tablet elementor-widget elementor-widget-table-of-contents\" data-id=\"77cdcf2\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;headings_by_tags&quot;:[&quot;h2&quot;],&quot;exclude_headings_by_selector&quot;:&quot;elementor-toc__heading-anchor-20&quot;,&quot;marker_view&quot;:&quot;bullets&quot;,&quot;icon&quot;:{&quot;value&quot;:&quot;&quot;,&quot;library&quot;:&quot;&quot;},&quot;collapse_subitems&quot;:&quot;yes&quot;,&quot;no_headings_message&quot;:&quot;No headings were found on this page.&quot;,&quot;minimize_box&quot;:&quot;yes&quot;,&quot;minimized_on&quot;:&quot;tablet&quot;,&quot;hierarchical_view&quot;:&quot;yes&quot;,&quot;min_height&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}\" data-widget_type=\"table-of-contents.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-toc__header\">\n\t\t\t\t\t\t<h4 class=\"elementor-toc__header-title\">\n\t\t\t\tThe pentest\t\t\t<\/h4>\n\t\t\t\t\t\t\t\t\t\t<div class=\"elementor-toc__toggle-button elementor-toc__toggle-button--expand\" role=\"button\" tabindex=\"0\" aria-controls=\"elementor-toc__77cdcf2\" aria-expanded=\"true\" aria-label=\"Open table of contents\"><i aria-hidden=\"true\" class=\"fas fa-chevron-down\"><\/i><\/div>\n\t\t\t\t<div class=\"elementor-toc__toggle-button elementor-toc__toggle-button--collapse\" role=\"button\" tabindex=\"0\" aria-controls=\"elementor-toc__77cdcf2\" aria-expanded=\"true\" aria-label=\"Close table of contents\"><i aria-hidden=\"true\" class=\"fas fa-chevron-up\"><\/i><\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<div id=\"elementor-toc__77cdcf2\" class=\"elementor-toc__body elementor-toc__list-items--collapsible\">\n\t\t\t<div class=\"elementor-toc__spinner-container\">\n\t\t\t\t<i class=\"elementor-toc__spinner eicon-animation-spin eicon-loading\" aria-hidden=\"true\"><\/i>\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7972af1 elementor-widget elementor-widget-spacer\" data-id=\"7972af1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-433fedb elementor-widget elementor-widget-heading\" data-id=\"433fedb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How does a pentest work?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ea6575a elementor-widget elementor-widget-text-editor\" data-id=\"ea6575a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Pentesting helps with a crucial task for IT and security teams within any organization. It is a technique used to identify vulnerabilities in a network for the purpose of proving the vulnerabilities. By performing pen testing, organizations can proactively address potential problems and risks before they are exploited by malicious parties. Pentests use several tools to examine various aspects of a network, such as application behavior and the effectiveness of security measures. Thus, by understanding the basics of pen testing, organizations can make the best use of their resources to strengthen their security. Therefore, it is also crucial for organizations to conduct a thorough pen test by a certified party.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-05db195 elementor-widget elementor-widget-heading\" data-id=\"05db195\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How does a pentest work?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ff35ce2 elementor-widget elementor-widget-text-editor\" data-id=\"ff35ce2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The process of a pentest at NFIR begins with an intake meeting with the client. In this conversation, the research area, or scope, is determined together and the most effective approach is advised. It is essential to clearly define the objectives and exact scope of the pentest. After this conversation, NFIR prepares a detailed quote that includes the job description, the chosen pen testing method, the expected timeframe and cost. This quote also includes the contact information for the NFIR team. If there is potential contact with personal data during the pentest, it is necessary for the client to offer a processor agreement to NFIR in advance.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7dd1df0 elementor-widget elementor-widget-heading\" data-id=\"7dd1df0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The 7 phases of a penetration test<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-09dd1b1 elementor-widget elementor-widget-text-editor\" data-id=\"09dd1b1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>After the quote and indemnification statement are signed, the pen test will be scheduled in consultation with the client. Penetration testing is a structured process designed to evaluate the security of systems and applications. This process is carried out in seven successive stages. The phases range from gathering information to reassessing security after implementing recommendations. These stages provide a thorough and systematic assessment of potential vulnerabilities.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7eb5e41 elementor-widget elementor-widget-heading\" data-id=\"7eb5e41\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Your pen testing in stages  <\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d531034 elementor-widget elementor-widget-text-editor\" data-id=\"d531034\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Pen tests go through specific phases. <span style=\"color: var(--ast-global-color-3); font-size: 1rem; font-weight: inherit;\">The seven phases during a penetration test are:<\/span><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-e4b5e69 e-con-full e-flex e-con e-child\" data-id=\"e4b5e69\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-77832a9 e-con-full e-flex e-con e-child\" data-id=\"77832a9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-da44030 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"da44030\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"icon icon-checkmark\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Phase 1: Intelligence Gathering<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"icon icon-checkmark\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Phase 2: Intelligence Analysis<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"icon icon-checkmark\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Phase 3: Vulnerability analysis<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"icon icon-checkmark\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Phase 4: Exploitation<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"icon icon-checkmark\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Phase 5: Post-Exploitation.<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"icon icon-checkmark\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Phase 6: Reporting<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"icon icon-checkmark\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Phase 7: Re-Audit<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f9a663c elementor-align-left pentest-aanvragen-button elementor-widget elementor-widget-button\" data-id=\"f9a663c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"#pentest-hoge-kwaliteit\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Learn more about the 7 phases of pen testing<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-40c0c7c e-con-full e-flex e-con e-child\" data-id=\"40c0c7c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ea4d518 elementor-widget elementor-widget-image\" data-id=\"ea4d518\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/11\/7-fases-penetratietest-nfir.png\" data-elementor-open-lightbox=\"yes\" data-elementor-lightbox-title=\"Pentesting: this is what you need to know about it\" data-elementor-lightbox-description=\"Pentesting: this is what you need to know about it - Your Cyber Security Specialist | NFIR - pentest\" data-e-action-hash=\"#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6MzUxMzQsInVybCI6Imh0dHBzOlwvXC93d3cuY3liZXItc2VjdXJpdHktb25saW5lLm5sXC93cC1jb250ZW50XC91cGxvYWRzXC8yMDIzXC8xMVwvNy1mYXNlcy1wZW5ldHJhdGlldGVzdC1uZmlyLnBuZyJ9\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"546\" height=\"1024\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/11\/7-fases-penetratietest-nfir-546x1024.png\" class=\"attachment-large size-large wp-image-35134\" alt=\"pentest: 7 stages of penetration testing or penetration testing\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/11\/7-fases-penetratietest-nfir-546x1024.png 546w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/11\/7-fases-penetratietest-nfir-160x300.png 160w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/11\/7-fases-penetratietest-nfir-768x1440.png 768w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/11\/7-fases-penetratietest-nfir.png 800w\" sizes=\"(max-width: 546px) 100vw, 546px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-600fed05 e-flex e-con-boxed e-con e-parent\" data-id=\"600fed05\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-5f54f9ef elementor-widget elementor-widget-heading\" data-id=\"5f54f9ef\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">From pen testing to clear reporting!<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-462994e e-flex e-con-boxed e-con e-parent\" data-id=\"462994e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-81c7100 elementor-widget elementor-widget-template\" data-id=\"81c7100\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"template.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-template\">\n\t\t\t\t\t<div data-elementor-type=\"container\" data-elementor-id=\"117276\" class=\"elementor elementor-117276 elementor-117273 elementor-117273\" data-elementor-post-type=\"elementor_library\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6745e235 e-flex e-con-boxed e-con e-parent\" data-id=\"6745e235\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-707aae57 elementor-widget elementor-widget-template\" data-id=\"707aae57\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"template.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-template\">\n\t\t\t\t\t<div data-elementor-type=\"container\" data-elementor-id=\"117196\" class=\"elementor elementor-117196 elementor-117192 elementor-117192 elementor-117192\" data-elementor-post-type=\"elementor_library\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4efb0e00 e-flex e-con-boxed e-con e-parent\" data-id=\"4efb0e00\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-5250abe e-grid e-con-boxed e-con e-child\" data-id=\"5250abe\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-3efcb83b e-con-full e-flex e-con e-child\" data-id=\"3efcb83b\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1b89f400 elementor-widget elementor-widget-heading\" data-id=\"1b89f400\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Step 1: intake<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8cf84b2 elementor-widget elementor-widget-text-editor\" data-id=\"8cf84b2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span dir=\"ltr\">During the intake, we discuss the scope components and attack scenarios of the pen test. An ethical hacker from NFIR is also present during the intake.<br \/>The intake is an important starting point because we would like to test all components within the scope of the pen test and identify all vulnerabilities. Based on the intake, we provide an hourly estimate and proposal.<\/span><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7efbe9de e-con-full e-flex e-con e-child\" data-id=\"7efbe9de\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-129d86c6 elementor-widget elementor-widget-heading\" data-id=\"129d86c6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Step 2: Proposal and agreements<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1baee779 elementor-widget elementor-widget-text-editor\" data-id=\"1baee779\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\">After you receive the hour estimate and proposal, we will be happy to discuss your questions.<br \/>In consultation, we will find a suitable time to perform the pen test.<\/span><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1cd0b31f e-con-full e-flex e-con e-child\" data-id=\"1cd0b31f\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4a7d44d0 elementor-widget elementor-widget-heading\" data-id=\"4a7d44d0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Step 3. implementation<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-479406f4 elementor-widget elementor-widget-text-editor\" data-id=\"479406f4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\">During the pen test, we keep you informed about progress and vulnerabilities.<br \/>Critical vulnerabilities are reported immediately so that they can be resolved as soon as possible.<\/span><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-540f043e e-con-full e-flex e-con e-child\" data-id=\"540f043e\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6fd690f1 elementor-widget elementor-widget-heading\" data-id=\"6fd690f1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Step 4: Results<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-77fa72be elementor-widget elementor-widget-text-editor\" data-id=\"77fa72be\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\">The vulnerabilities are documented in a clear and complete pen testing report. A standard part of our pentest services is to explain the findings following the delivered pentest report.  <br \/>This explanation is greatly appreciated by our clients.<\/span><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7e33fd5d e-con-full e-flex e-con e-child\" data-id=\"7e33fd5d\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2fef4b93 elementor-widget elementor-widget-heading\" data-id=\"2fef4b93\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Step 5: Perfecting<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-239724a7 elementor-widget elementor-widget-text-editor\" data-id=\"239724a7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\">Thanks to the clear insights, you are going to mitigate the vulnerabilities.<br \/>If required, we can arrange for a retest after the vulnerabilities have been mitigated. Based on this retest, you will receive a new pen test report and have confirmation that the vulnerabilities have actually been fixed<\/span><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5ccbb57f e-con-full e-flex e-con e-child\" data-id=\"5ccbb57f\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-75347d2c elementor-widget elementor-widget-heading\" data-id=\"75347d2c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Let us assess your risks!<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-44e14455 elementor-widget elementor-widget-text-editor\" data-id=\"44e14455\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Find out how safe you really are and contact us today.  <\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2fc8f574 elementor-align-center pentest-aanvragen-button elementor-widget elementor-widget-button\" data-id=\"2fc8f574\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"#form-top-pentesten\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Contact about pen testing<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-4ab240f e-flex e-con-boxed e-con e-parent\" data-id=\"4ab240f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-79308ae e-con-full e-flex e-con e-child\" data-id=\"79308ae\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4437cce elementor-widget elementor-widget-heading\" data-id=\"4437cce\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The scope of the test<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c60ce9f elementor-widget elementor-widget-text-editor\" data-id=\"c60ce9f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Before confirming the assignment, the <b>scope<\/b> of the pen test must be clear. <span style=\"color: var(--ast-global-color-3); font-size: 1rem; font-weight: inherit;\">Determining the scope of the pen test is crucial to a successful security audit. <\/span><span style=\"font-style: inherit; font-weight: inherit; color: var(--ast-global-color-3);\">The scope is the object of investigation, also known as the area of investigation. <\/span> <span style=\"color: var(--ast-global-color-3); font-size: 1rem; font-weight: inherit;\">When performing a pen test, IT professionals take a meticulous approach to identifying vulnerabilities in your organization. By defining the scope, or scope, of the pentest, it is possible to determine which systems and networks will be examined.<\/span><span style=\"color: var(--ast-global-color-3); font-size: 1rem; font-weight: inherit;\"> <\/span><span style=\"color: var(--ast-global-color-3); font-style: inherit; font-weight: inherit;\">Depending on the type of pen test, no, limited or complete information about the scope will be shared by the client with NFIR. <\/span><span style=\"font-style: inherit; font-weight: inherit; color: var(--ast-global-color-3);\">This helps identify potential risks and threats specific to your organization.<\/span><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8e975a1 elementor-widget elementor-widget-heading\" data-id=\"8e975a1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Types of penetration tests<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-adc513c elementor-widget elementor-widget-text-editor\" data-id=\"adc513c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>There are different types of attack scenarios in pen testing.<br \/>\nEach attack scenario has its unique focus and methodology.  The purpose of pen testing is to evaluate an organization&#8217;s IT security and identify potential system vulnerabilities. It may take several days to complete a pentest, depending on the scope. A <b>certified<\/b> ethical hacker is used to perform the pen test. These ethical hackers use their skills to test system security and discover any vulnerabilities. Pen testing makes it possible to test an organization&#8217;s security measures and then improve them.  <b>The ultimate goal, of course, is to prevent future cyberattacks.<\/b><\/p>\n<p>To identify technical security risks or misuse of an IT infrastructure, website, (mobile) application or link(s), there are roughly three types of pentests that can be performed. The different types of attack scenarios that may be considered during the pen test are the <a href=\"https:\/\/www.cyber-security-online.nl\/en\/7-important-questions-about-pen-testing\/\">Black Box<\/a>, <a href=\"https:\/\/www.cyber-security-online.nl\/en\/7-important-questions-about-pen-testing\/\">Grey Box<\/a> and <a href=\"https:\/\/www.cyber-security-online.nl\/en\/7-important-questions-about-pen-testing\/\">White Box<\/a>. The attack scenarios are explained below.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-33e2942 e-con-full e-flex e-con e-child\" data-id=\"33e2942\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-23faef7 e-con-full e-flex e-con e-child\" data-id=\"23faef7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-74e412c elementor-position-top elementor-widget elementor-widget-image-box\" data-id=\"74e412c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><figure class=\"elementor-image-box-img\"><img decoding=\"async\" width=\"256\" height=\"360\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2020\/05\/Blackbox-title-kader.png\" class=\"attachment-full size-full wp-image-2726\" alt=\"Black box pen testing hacker organization applications security information\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2020\/05\/Blackbox-title-kader.png 256w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2020\/05\/Blackbox-title-kader-213x300.png 213w\" sizes=\"(max-width: 256px) 100vw, 256px\" \/><\/figure><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">Black Box pentest<\/h3><p class=\"elementor-image-box-description\">A Black Box audit can be compared to a real attack, like hackers would do. No information has been provided by the client in advance. Our ethical hackers will use open source research (OSINT) to map out your environment. So they can look for vulnerabilities.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-65d51a6 e-con-full e-flex e-con e-child\" data-id=\"65d51a6\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fbd585d elementor-position-top elementor-widget elementor-widget-image-box\" data-id=\"fbd585d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><figure class=\"elementor-image-box-img\"><img decoding=\"async\" width=\"256\" height=\"360\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2020\/05\/Greybox-title-kader.png\" class=\"attachment-full size-full wp-image-2727\" alt=\"Grey box pen testing risk hackers automated network penetration test the netherlands\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2020\/05\/Greybox-title-kader.png 256w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2020\/05\/Greybox-title-kader-213x300.png 213w\" sizes=\"(max-width: 256px) 100vw, 256px\" \/><\/figure><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">Grey Box Pentest<\/h3><p class=\"elementor-image-box-description\">In this pentest, ethical hackers identify vulnerabilities in your (web) application, website, IT infrastructure, API links and mobile apps, both with and without information. <\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-82a10a3 e-con-full e-flex e-con e-child\" data-id=\"82a10a3\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-095c50e elementor-position-top elementor-widget elementor-widget-image-box\" data-id=\"095c50e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><figure class=\"elementor-image-box-img\"><img decoding=\"async\" width=\"256\" height=\"360\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2020\/05\/Whitebox-title-kader.png\" class=\"attachment-full size-full wp-image-2728\" alt=\"white box pentesting ethical hardware vulnerability pentester security audit computer systems\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2020\/05\/Whitebox-title-kader.png 256w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2020\/05\/Whitebox-title-kader-213x300.png 213w\" sizes=\"(max-width: 256px) 100vw, 256px\" \/><\/figure><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">White Box Pentest<\/h3><p class=\"elementor-image-box-description\">(a.k.a. Crystal box). During a White Box audit, all information is provided in advance in order to specifically search for vulnerabilities. Think of source code, defined scope, roles\/rights matrix and functionalities list. <\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3e96a56 elementor-widget elementor-widget-heading\" data-id=\"3e96a56\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The testing methodologies of a pentest explained<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b7537b0 elementor-widget elementor-widget-text-editor\" data-id=\"b7537b0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>When performing a pentest, it is crucial to use the right testing methodology to ensure the optimal level of security within your IT infrastructure. While each organization is unique in terms of hardware and network, all professional pen testing follows a standardized process that largely consists of<b> identifying<\/b>, <b>analyzing<\/b> and <b>exploiting <\/b>potential vulnerabilities. An ethical hacker approaches infrastructure from the point of view of a potential attacker. It is important to carefully select both the scope of the pentest and the specific type of pentest to ensure that all possible attack vectors are considered. Regardless of the testing method chosen, it&#8217;s all about optimizing your organization&#8217;s security.<\/p>\n<p>To perform a successful pen test, NFIR uses several methods for information security testing. The three most important standards (depending on the environment being tested) are the Penetration Execution Standard (PTES) and the 2 standards of the organization Open Web Application Security Project (OWASP). The standards are; The <a style=\"background-color: #ffffff;\" href=\"https:\/\/owasp.org\/www-project-web-security-testing-guide\/\">WSTG<\/a> and the <a style=\"background-color: #ffffff;\" href=\"https:\/\/mas.owasp.org\/MASTG\/\">MASTG<\/a>. <a style=\"background-color: #ffffff;\" href=\"https:\/\/www.first.org\/cvss\/v4-0\/\" target=\"_blank\" rel=\"noopener\">The Common Vulnerability Scoring System version 4.0<\/a>, abbreviated to the CVSS risk model, is used to determine the severity of a vulnerability. This international model is used by NFIR to classify security breaches.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-632f73d elementor-widget elementor-widget-heading\" data-id=\"632f73d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Why and when do you conduct a pentest?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-db830c1 elementor-widget elementor-widget-text-editor\" data-id=\"db830c1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>There are several reasons to perform a pentest in your IT organization. The primary goal of pen testing is to gain an understanding of the strength of your organization&#8217;s security infrastructure against possible hacker attacks. Pentesting helps organizations identify vulnerabilities (also known as &#8220;vulnerabilities&#8221;) in their networks, systems or applications. These can then be addressed <b>before<\/b> a malicious hacker can exploit them. Pentests also give organizations a better understanding of how a hacker might attempt to circumvent security. <b>We recommend performing pen tests periodically,<\/b> not only after major infrastructure changes, but also as a security review to proactively protect your organization.<br \/>\nAs such, the results of the pen test are best viewed as a snapshot in time.   <\/p>\n<p>Since 25 May 2018, the General Data Protection Regulation (AVG) has entered into force, which stipulates that personal data must be protected against leaks and misuse. By taking appropriate technical and organizational measures, personal data can be protected. A pentest is one of these appropriate measures because it provides insight into the risks and vulnerabilities of the environments investigated. It also checks whether (company) sensitive information is properly secured. Based on the advice from a pentest, risks and vulnerabilities can be mitigated and an organisation can take its security to a higher level. Having a pentest carried out is a valuable assessment of the systems examined, in which a report discusses the risks and vulnerabilities identified in a report and suggests possible recommendations for improvement.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d9888e3 elementor-widget elementor-widget-heading\" data-id=\"d9888e3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Looking for more information about pen testing?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8e63135 elementor-widget elementor-widget-text-editor\" data-id=\"8e63135\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>NFIR employs specialists who know everything there is to know about pen testing and carefully uncover vulnerabilities. Would you like to know what we can do for you with our pentests? Then contact us! We perform pentests on your (web) application, website, IT infrastructure, links (APIs) and mobile apps and can review code from your software if required.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-2dd956c e-con-full e-flex e-con e-child\" data-id=\"2dd956c\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ade1bd2 elementor-widget elementor-widget-text-editor\" data-id=\"ade1bd2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Discover Our Pentest Services!<\/strong> <br \/>Do you need a thorough pen test for your application, website, IT infrastructure or mobile apps? <br \/>NFIR&#8217;s experts carefully uncover vulnerabilities. <br \/><a href=\"#form-top-pentesten\"><strong>Contact us directly to see how we can help you!<\/strong><\/a><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f801f23 elementor-widget elementor-widget-text-editor\" data-id=\"f801f23\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-size: 16px;\">Pentesting is essential for any organization. They provide insight into vulnerabilities within your platform or workplace that could potentially be exploited by malicious parties. Incidents such as hacking often expose these vulnerabilities. By proactively performing pen testing, these vulnerabilities can be identified and addressed before they pose a real danger. Regular pentests contribute to a more robust security of your organization and reduce the likelihood of successful cyber attacks. This makes your business a safer place to operate. An important reference point in identifying these vulnerabilities is the Common Vulnerability Exposures (CVE) database, which provides detailed information about vulnerabilities in computer systems and networks. Many penetration test reports refer to this database. <\/span><a style=\"font-size: 16px; background-color: #ffffff;\" href=\"https:\/\/www.cyber-security-online.nl\/en\/media\/\">Also check out the latest Threat Intelligence reports from NFIR<\/a><span style=\"font-size: 16px;\">. <\/span> <\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7e67fed e-flex e-con-boxed e-con e-parent\" data-id=\"7e67fed\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-27897fb e-con-full e-flex e-con e-child\" data-id=\"27897fb\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-45bcc1a elementor-widget elementor-widget-html\" data-id=\"45bcc1a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Wat is een pentest?\",\"acceptedAnswer\":[{\"@type\":\"Answer\",\"text\":\"Een pentest is een test waarbij ethical hackers systemen onderzoeken op kwetsbaarheden. De ethical hackers proberen op verscheidene manieren zwakke plekken in systemen aan het licht te brengen. Door een combinatie van geautomatiseerde tooling en creativiteit trachten de ethical hackers ongeautoriseerd toegang tot krijgen tot informatie en\/of systemen. Een pentest vindt altijd plaats in opdracht en met toestemming van de eigenaren van de systemen die getest worden. Als er geen vrijwaringsverklaring, is er namelijk sprake van computervredebreuk. Nadat een pentest is uitgevoerd, worden de bevindingen door middel van een rapportage met de opdrachtgever gedeeld. In deze rapportage worden de gevonden kwetsbaarheden nauwkeurig beschreven, de scores middels de CVVS bepaald (Common Vulnerability Scoring System) en adviezen waarmee de kwetsbaarheden verholpen kunnen worden aangedragen. Aangeraden wordt om een pentest periodiek uit te voeren, omdat een pentest een momentopname betreft en omgevingen vaak aan veranderingen onderhevig zijn\"}]},{\"@type\":\"Question\",\"name\":\"Hoe gaat een pentest in zijn werk?\",\"acceptedAnswer\":[{\"@type\":\"Answer\",\"text\":\"Een pentest van NFIR bestaat uit verschillende onderdelen. Er wordt gestart met een intakegesprek met de opdrachtgever. Tijdens dit intakegesprek bepalen wij samen met de opdrachtgever het onderzoeksgebied (de scope) van de pentest en adviseren wij over de wijze waarop wij voor uw organisatie de meest waardevolle pentest kunnen uitvoeren. Het is belangrijk dat helder op papier komt te staan wat het doel is van de pentest en wat de exacte scope is. Van de opdrachtgever zal informatie benodigd zijn om de werkzaamheden van de pentest goed in te kunnen schatten. Op basis van het intakegesprek zal een offerte opgesteld worden voor de opdrachtgever. In de offerte staat beschreven wat de opdrachtomschrijving, de scope, de pentestmethode en het tijdsverloop is. Daarnaast staan de algemene en specifieke vereisten voor de start van de pentest opgesomd. Ook de contactgegevens van het NFIR team, de tarieven en projectenkosten worden beschreven in de offerte. Indien NFIR in aanraking kan komen met persoonsgegevens zal, voorafgaand aan de pentest, ook een verwerkersovereenkomst moeten worden aangeboden door de opdrachtgever.\"}]},{\"@type\":\"Question\",\"name\":\"De 7 fasen van een penetratietest\",\"acceptedAnswer\":[{\"@type\":\"Answer\",\"text\":\"Nadat de offerte en de vrijwaringsverklaring zijn ondertekend, zal de pentest ingepland worden in overleg met de opdrachtgever. Wij onderscheiden zeven fasen tijdens een penetratietest. Deze zeven fasen zijn:\\n\\nFase 1 \u2013 Intelligence Gathering: Deze fase bestaat uit het verzamelen van zoveel mogelijk informatie uit beschikbare bronnen. Dit kunnen openbare bronnen (OSINT) zijn en informatie afkomstig van de klant. Door de klant kan informatie worden aangeleverd zoals netwerktekeningen en een IP nummerplan. Deze beschikbare bronnen hoeven niet noodzakelijkerwijs deel uit te maken van de van tevoren ge\u00efdentificeerde scope.\\nFase 2 \u2013 Threat Modeling: Gedurende deze fase wordt de informatie georganiseerd en vastgesteld welke informatie relevant is voor de penetratietest. U kunt hierbij denken aan het identificeren van waardevolle informatie, uitdenken van een aanvalsmethodiek en onderzoeken van de bedreigingen.\\nFase 3 \u2013 Vulnerability Analysis: Nadat alle informatie is verzameld wordt in deze fase gezocht naar kwetsbaarheden in systemen en applicaties. Er wordt hierbij gebruik gemaakt van tooling die automatisch zoekt naar kwetsbaarheden. Daarnaast wordt er door een ethische hacker op een creatieve wijze handmatig gezocht en gekeken naar kwetsbaarheden. Tijdens deze fase wordt er gebruik gemaakt van diverse internationale standaarden zoals OWASP Top 10, OSTMM en OWASP MSTG.\\nFase 4 \u2013 Exploitation: Tijdens de exploitation fase is het doel toegang verkrijgen tot het systeem. De reeds verzamelde informatie wordt gebruikt om op een zorgvuldige wijze aanvallen uit te voeren. Deze aanvallen hebben als doel om de ge\u00efdentificeerde kwetsbaarheden te bevestigen.\\nFase 5 \u2013 Post-Exploitation: In deze fase wordt er vastgesteld wat de waarde is van het gecompromitteerde systeem. Dit is afhankelijk van welke data is gevonden en of deze bruikbaar is om het netwerk verder te compromitteren.\\nFase 6 \u2013 Reporting: Alle bevindingen zullen worden samengebracht in een compleet en helder uitgewerkt rapport. Dit rapport bevat een beschrijving van de bevindingen, een scoresysteem (CVSS) waarbij de kwetsbaarheden een classificatie krijgen, de mogelijke impact en onze aanbeveling die uw organisatie helpt met het oplossen van de gevonden kwetsbaarheden.\\nFase 7 \u2013 Re-audit: Op basis van de aanbevelingen kunnen de gevonden kwetsbaarheden door uw eigen organisatie (of externe partij) worden opgelost. Zodra de kwetsbaarheden zouden moeten zijn opgelost, kan via een re-audit worden onderzocht en gerapporteerd of de kwetsbaarheden daadwerkelijk zijn opgelost. U kunt een hertest rapportage bijvoorbeeld gebruiken om externe partijen (afnemers, partners, auditors, etc.) te overtuigen van de technische weerbaarheid van uw systemen en applicaties. Op deze manier bent u verzekerd van een onpartijdig en scherp oordeel over de aangebrachte verbeteringen. Een re-audit kan alleen worden begroot na voltooiing van de initi\u00eble penetratietest.\"}]},{\"@type\":\"Question\",\"name\":\"Soorten pentesten\",\"acceptedAnswer\":[{\"@type\":\"Answer\",\"text\":\"Om technische beveiligingsrisico\u2019s of misbruik van een IT-infrastructuur, website, (mobiele) applicatie of koppeling(en) in kaart te brengen, zijn er ruwweg drie soorten pentesten die uitgevoerd kunnen worden. De verschillende soorten aanvalsscenario\u2019s die mogelijk aan bod komen tijdens de pentest zijn de Black Box, Grey Box en White Box. Hieronder worden de aanvalsscenario\u2019s toegelicht.\"}]},{\"@type\":\"Question\",\"name\":\"Black Box Pentest\",\"acceptedAnswer\":[{\"@type\":\"Answer\",\"text\":\"Een Black Box pentest houdt in dat vooraf geen informatie over de omgeving wordt gedeeld met de pentesters. Meestal wordt el een onderzoeksgebied (scope) vastgesteld, zodat de pentest wel gelimiteerd is. De pentesters gaan bij deze variant te werk als echte hackers en maken gebruikt van Open Bronnen onderzoek, diverse scanners en een dosis creativiteit om ongeautoriseerd toegang te verkrijgen tot de omgeving binnen de scope. Als u voor het eerst een pentest laat uitvoeren en daarbij een algemeen beeld wilt krijgen van uw beveiliging, is het nuttig om een Black Box pentest uit te laten voeren.\"}]},{\"@type\":\"Question\",\"name\":\"Grey Box pentest\",\"acceptedAnswer\":[{\"@type\":\"Answer\",\"text\":\"Een Grey Box-penetratietest is een tussenvorm van de Black Box en White Box pentest, waarbij de pentesters beperkte inloggegevens en -informatie ter beschikking hebben. Door de beperkte informatie die de pentesters ontvangen, zijn zij beter ge\u00efnformeerd dan een hacker. De Grey Box pentest wordt over het algemeen toegepast om te onderzoeken hoe veilig een omgeving is vanuit het perspectief van een gebruiker, medewerker of klant.\"}]},{\"@type\":\"Question\",\"name\":\"White Box pentest\",\"acceptedAnswer\":[{\"@type\":\"Answer\",\"text\":\"Met een pentest op basis van het White Box -principe wordt alle informatie van tevoren gedeeld, hierdoor kan een pentest heel grondig worden uitgevoerd. Deze methode vraagt wel veel tijd omdat de gehele scope gedetailleerd onderzocht moet worden. Meestal wordt deze methode toegepast op een afgebakend onderzoeksgebied.\"}]},{\"@type\":\"Question\",\"name\":\"De testmethodieken\",\"acceptedAnswer\":[{\"@type\":\"Answer\",\"text\":\"Om een succesvolle pentest uit te voeren, gebruikt NFIR verschillende methoden voor het testen van informatiebeveiliging. De drie belangrijke standaarden zijn de Penetration Execution Standard (PTES), Open Source Security Testing Methodology Manual (OSSTMM) en het Open Web Application Security Project (OWASP). Door gebruik te maken van deze normen, zorgt NFIR voor een succesvol en grondig uitgevoerd veiligheidsonderzoek en krijgt de opdrachtgever zekerheid over de volledigheid van de uitgevoerde pentest.\\n\\nHet Common Vulnerability Scoring System versie 3, afgekort tot het CVSS-risicomodel, wordt gebruikt om de ernst van een kwetsbaarheid te bepalen. Dit model wordt gebruikt door NFIR om de beveiligingslekken te classificeren. Het scoresysteem werkt op basis van negen verschillende basisparameters, die samen de risico score bepalen. Die basisparameters zijn:\\n\\nHet aanvalsoppervlak waarop de aanval wordt uitgevoerd.\\nDe complexiteit van de uitvoering van de aanval, voor een aanvaller.\\nDe privileges (zoals bijvoorbeeld accounts) die nodig zijn om de aanval uit te voeren.\\nDe vorm van interactie met het slachtoffer die al dan niet nodig is om de aanval uit te voeren.\\nHet beheer van de \u2018scope\u2019 door een, al dan niet, externe partij die beslissingen neemt.\\nDe gevolgen voor de vertrouwelijkheid van het aangevallen systeem.\\nDe gevolgen voor de integriteit van het aangevallen systeem.\\nDe impact op de beschikbaarheid van het aangevallen systeem.\"}]},{\"@type\":\"Question\",\"name\":\"Waarom een Pentest uitvoeren?\",\"acceptedAnswer\":[{\"@type\":\"Answer\",\"text\":\"Sinds 25 mei 2018 is de Algemene verordening gegevensbescherming (AVG) in werking getreden, waarin voorgeschreven staat dat persoonsgegevens beschermd moeten worden tegen lekken en misbruik. Door passende technische en organisatorische maatregelen te nemen, kunnen persoonsgegevens worden beschermd. Een pentest behoort tot die passende maatregelen omdat het inzichtelijk maakt wat de risico\u2019s en kwetsbaarheden zijn van de onderzochte omgevingen. Hierbij wordt ook gecontroleerd of (bedrijfs)gevoelige informatie goed beveiligd is. Aan de hand van de adviezen uit een pentest kunnen risico\u2019s en kwetsbaarheden gemitigeerd worden en kan een organisatie haar beveiliging naar een hoger niveau brengen. Het laten uitvoeren van een pentest is een waardevolle beoordeling van de onderzochte systemen, waarbij in een rapportage geconstateerde risico\u2019s en kwetsbaarheden worden besproken en eventuele adviezen voor verbetering worden aangedragen.\"}]}]}<\/script>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-18c2dc9 elementor-widget elementor-widget-accordion\" data-id=\"18c2dc9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-2591\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-2591\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What is the difference between a pentest and a vulnerability scan<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-2591\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-2591\"><ol>\n<li>\n<p><strong>A vulnerability scan<\/strong> uses automated scans to discover known vulnerabilities. These vulnerabilities are then reported. It is an important first step in understanding potential weaknesses within a system.<\/p>\n<p><strong>A pen test goes one step further<\/strong>. During a pentest, not only are vulnerabilities identified, but they are actually exploited. This demonstrates what the actual consequence may be to a system or environment when compromised. The ethical hacker will use his experience and creativity to identify all the weaknesses of an environment, giving the organization a more realistic picture of the risks they face.<\/p>\n<p><a href=\"https:\/\/www.cyber-security-online.nl\/en\/7-important-questions-about-pen-testing\/\">read 7 important questions in a pen test<\/a><\/p>\n<\/li>\n<\/ol>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-2592\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-2592\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What methods do you use to perform pentests?<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-2592\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-2592\"><p>When performing a pentest, various international standards and methodologies are used to discover and classify vulnerabilities. Some of the key standards applicable to the assignment include:<\/p>\n<ul>\n<li><a href=\"http:\/\/www.pentest-standard.org\/\" target=\"_blank\" rel=\"noopener\">Penetration Testing Execution Standard (PTES)<\/a>: methodology for the purpose of infrastructure pen testing.<\/li>\n<li><a href=\"https:\/\/owasp.org\/www-project-web-security-testing-guide\/\" target=\"_blank\" rel=\"noopener\">OWASP WSTG<\/a>: Standard for the purpose of Web application pentesting.<\/li>\n<li><a href=\"https:\/\/owasp.org\/www-project-top-ten\/\" target=\"_blank\" rel=\"noopener\">OWASP Top 10<\/a>: The 10 most critical web application vulnerabilities.<\/li>\n<li><a href=\"https:\/\/owasp.org\/www-project-api-security\/\" target=\"_blank\" rel=\"noopener\">OWASP API Security Top 10<\/a>: The 10 most critical API vulnerabilities.<\/li>\n<li><a href=\"https:\/\/mas.owasp.org\/\" target=\"_blank\" rel=\"noopener\">OWASP MASTG<\/a>: Standard for the purpose of mobile application pentesting.<\/li>\n<li><a href=\"https:\/\/www.first.org\/cvss\/v3-1\/\" target=\"_blank\" rel=\"noopener\">Common Vulnerability Scoring System (CVSS)<\/a>: Used to classify the severity of vulnerabilities.<\/li>\n<\/ul>\n<p>By using these standards, a pentest can be performed in a structured and thorough manner, and the results can be reported in a clear and comparable way.<\/p>\n<h4>The Penetration Testing Execution Standard (PTES).<\/h4>\n<p>The Penetration Testing Execution Standard (PTES) consists of several main components. These cover everything about a penetration test, namely:<\/p>\n<ol>\n<li>The initial communication and reasoning behind a pentest;<\/li>\n<li>The information gathering and threat modelling phases, where testers work behind the scenes to gain a better understanding of the tested organisation;<\/li>\n<li>Vulnerability assessment, exploitation and post-exploitation, which addresses the technical security expertise of the testers and combines it with the business insight of the assignment;<\/li>\n<li>Reporting, which captures the entire process in a way that makes sense to the customer and provides them with the most value.<\/li>\n<\/ol>\n<h4>OWASP WSTG<\/h4>\n<p>The Web Security Testing Guide (WSTG) project is the premier cybersecurity testing resource for Web application developers and security professionals. The WSTG is a comprehensive guide to testing the security of Web applications and Web services. Created through the combined efforts of cybersecurity professionals and dedicated volunteers, the WSTG provides a framework of best practices used by penetration testers and organizations around the world.<\/p>\n<h4>OWASP MASTG<\/h4>\n<p>The OWASP Mobile Application Security Testing guide is a mobile app security standard and comprehensive testing guide that covers the processes, techniques and tools used during a mobile app security test, as well as a comprehensive set of test cases that allow testers to deliver consistent and complete results.<\/p>\n<h4>Common Vulnerability Scoring System (CVSS).<\/h4>\n<p>The Common Vulnerability Scoring System (CVSS) standard provides an open framework for disclosing the characteristics and consequences of software and hardware security vulnerabilities. The quantitative model is designed to ensure consistent and accurate measurement while allowing users to see the underlying vulnerability characteristics used to generate the scores.<\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-2593\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-2593\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What is the Common Vulnerability Scoring System (CVSS 4.0)<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-2593\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-2593\"><p>CVSS is an industry standard for assessing the severity of security vulnerabilities in computer systems. It provides scores based on various metrics to determine the impact and exploitability of vulnerabilities. Scores range from 0 to 10, with 10 being the most severe. CVSS consists of three sets of metrics: Base Metrics (inherent vulnerability), Temporal Metrics (evolution of vulnerability) and Environmental Metrics (context of vulnerability). These scores help prioritize responses to vulnerabilities.<\/p>\n<ul>\n<li>CVSS is an industry standard for assessing computer security vulnerabilities.<\/li>\n<li>It assigns scores based on Base Metrics (inherent vulnerability), Temporal Metrics (evolution of vulnerability) and Environmental Metrics (context of vulnerability).<\/li>\n<li>Scores range from 0 to 10, with 10 indicating the most severe vulnerability.<\/li>\n<li>CVSS helps prioritize security responses and resources.<\/li>\n<li>It includes metrics such as access capabilities, attack complexity, authentication requirements and impact on confidentiality, integrity and data availability.<\/li>\n<li>CVSS version 3 (CVSS v3) was introduced in June 2015 to address some shortcomings in previous versions.<\/li>\n<li>CVSS v3 introduced new metrics such as User Interaction and Privileges Required to assess security vulnerabilities in more detail.<\/li>\n<\/ul>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-2594\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-2594\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How long does a pentest take?<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-2594\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-2594\"><p>Depending on the size of the job, a careful assessment is made as to whether multiple people should be put on a pentest to reduce the length of the job. The duration of a pentest can vary depending on the environment being tested and the complexity of the attack scenarios being used. Generally, a pentest covers a period of 2 to 4 weeks. This period includes not only the execution of the test itself, but also the preparation, analysis and explanation of the final report.<\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-2595\" class=\"elementor-tab-title\" data-tab=\"5\" role=\"button\" aria-controls=\"elementor-tab-content-2595\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Black box or white box scenario?<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-2595\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"5\" role=\"region\" aria-labelledby=\"elementor-tab-title-2595\"><p>When choosing the right pentest platform, it is important to consider some important aspects. First, the platform must be able to identify vulnerabilities in your IT systems. In addition, the platform should provide tools to help your organization mitigate these vulnerabilities. The security functionalities of the platform are also crucial. It should allow for both &#8220;white box&#8221; and &#8220;black box&#8221; pen testing. Selecting the right pentest platform can help you maintain a better security posture and enable your IT and security teams to work more effectively. Is your organization already doing pen testing, or are you still looking for more information about pen testing? Remember, an informed choice can be critical to your organization&#8217;s security.<\/p>\n<ol>\n<li>A Black Box pentest means that no information about the environment is shared with the pen testers beforehand.<\/li>\n<li>With a pentest based on the White Box principle, all information about the environment is shared in advance.<\/li>\n<li>If you are having a pentest performed for the first time and want to get an overall picture of your security, it is useful to have a Black Box pen test performed.<\/li>\n<\/ol>\n<h3>What more does a grey-box pentest offer than a black-box?<\/h3>\n<ol>\n<li>A Black Box pentest is especially suitable when an environment is being pen tested for the first time and you want to get an overall picture of the security.<\/li>\n<li>A Grey Box Penetration Test is an intermediate form of the Black Box and White Box Penetration Test, in which the researchers have limited login details and information at their disposal.<\/li>\n<li>The Grey Box pentest is generally used to see how safe an environment is from the perspective of an employee or customer.<\/li>\n<\/ol>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-2596\" class=\"elementor-tab-title\" data-tab=\"6\" role=\"button\" aria-controls=\"elementor-tab-content-2596\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Make good arrangements about the pentest<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-2596\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"6\" role=\"region\" aria-labelledby=\"elementor-tab-title-2596\"><p>When it comes to IT security, there are some crucial questions you should be asking. Why? Because it helps identify potential vulnerabilities, and leads to effective security measures. A factor here is that &#8220;pentesting,&#8221; or penetration testing, is a crucial part of ethical hacking. It is not just a matter of ticking boxes, but a process that can take several days. A carefully conducted pen test can discover unauthorized access to your IT systems and expose these vulnerabilities. So choose the right pentest partner NFIR and maintain control of your security. Look beyond IT, because pen testing is also about overall corporate security!<\/p>\n<h3>Make good arrangements about the pentest<\/h3>\n<ol>\n<li>Make arrangements with each other when the information should be delivered, when the pentest will take place, what the pen test means for the daily operations within your company and when the report will be delivered.<\/li>\n<li>The assignment must be clear and the information required in advance must be provided on time, otherwise a pentest cannot start.<\/li>\n<\/ol>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-2597\" class=\"elementor-tab-title\" data-tab=\"7\" role=\"button\" aria-controls=\"elementor-tab-content-2597\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Penetration tests by our certified experts<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-2597\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"7\" role=\"region\" aria-labelledby=\"elementor-tab-title-2597\"><p>NFIR B.V. is known as your expert in pen testing and IT security. We understand that every organization is unique and therefore have a personalized approach for each IT environment. With our expertise, we identify vulnerabilities within your network and help your organization secure itself. Whether it is a simple pentest or a complex penetration test, NFIR strives to ensure the security of your network. Our pen testing services combine both security and IT knowledge to perform the most effective tests. We understand that your IT environment is an essential part of your organization&#8217;s functioning, so we strive to protect it from potential cyber attacks. NFIR is your trusted partner in pen testing and IT security.<\/p>\n<h3><span class=\"TextRun SCXW206924199 BCX0\" lang=\"NL-NL\" xml:lang=\"NL-NL\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW206924199 BCX0\"><span class=\"TextRun SCXW44007709 BCX0\" lang=\"NL-NL\" xml:lang=\"NL-NL\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW44007709 BCX0\">Certified and quality-focused Ethical Hackers<\/span><\/span><\/span><\/span><\/h3>\n<p><span class=\"TextRun SCXW206924199 BCX0\" lang=\"NL-NL\" xml:lang=\"NL-NL\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW206924199 BCX0\">Our skilled and professional ethical hackers have extensive experience, creativity and up-to-date professional knowledge. They have completed relevant training and are certified, such as: <\/span><\/span><\/p>\n<ul>\n<li><a class=\"Hyperlink SCXW206924199 BCX0\" href=\"https:\/\/www.offsec.com\/courses\/pen-200\/\" target=\"_blank\" rel=\"noopener\"><span class=\"TextRun Underlined SCXW206924199 BCX0\" lang=\"NL-NL\" xml:lang=\"NL-NL\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW206924199 BCX0\" data-ccp-charstyle=\"Hyperlink\">OSCP<\/span><\/span><\/a><\/li>\n<li><a class=\"Hyperlink SCXW206924199 BCX0\" href=\"https:\/\/www.offsec.com\/courses\/web-300\/\" target=\"_blank\" rel=\"noopener\"><span class=\"TextRun Underlined SCXW206924199 BCX0\" lang=\"NL-NL\" xml:lang=\"NL-NL\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW206924199 BCX0\" data-ccp-charstyle=\"Hyperlink\">OSWE<\/span><\/span><\/a><\/li>\n<li><a class=\"Hyperlink SCXW206924199 BCX0\" href=\"https:\/\/www.offsec.com\/courses\/pen-300\/\" target=\"_blank\" rel=\"noopener\"><span class=\"TextRun Underlined SCXW206924199 BCX0\" lang=\"NL-NL\" xml:lang=\"NL-NL\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW206924199 BCX0\" data-ccp-charstyle=\"Hyperlink\">OSEP<\/span><\/span><\/a><\/li>\n<li><a class=\"Hyperlink SCXW206924199 BCX0\" href=\"https:\/\/academy.hackthebox.com\/preview\/certifications\/htb-certified-penetration-testing-specialist\" target=\"_blank\" rel=\"noopener\"><span class=\"TextRun Underlined SCXW206924199 BCX0\" lang=\"NL-NL\" xml:lang=\"NL-NL\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW206924199 BCX0\" data-ccp-charstyle=\"Hyperlink\">CPTS<\/span><\/span><\/a><\/li>\n<li><a class=\"Hyperlink SCXW206924199 BCX0\" href=\"https:\/\/elearnsecurity.com\/product\/ewpt-certification\/\" target=\"_blank\" rel=\"noopener\"><span class=\"TextRun Underlined SCXW206924199 BCX0\" lang=\"NL-NL\" xml:lang=\"NL-NL\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW206924199 BCX0\" data-ccp-charstyle=\"Hyperlink\">eWPT<\/span><\/span><\/a><\/li>\n<\/ul>\n<p><span class=\"TextRun SCXW206924199 BCX0\" lang=\"NL-NL\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW206924199 BCX0\">In addition <\/span><span class=\"NormalTextRun SCXW206924199 BCX0\">NFIR<\/span><span class=\"NormalTextRun SCXW206924199 BCX0\"> holds a <\/span><\/span><a class=\"Hyperlink SCXW206924199 BCX0\" href=\"https:\/\/hetccv.nl\/keurmerken\/zakelijk\/digitale-veiligheid\/ccv-keurmerk-pentesten\/\" target=\"_blank\" rel=\"noopener\"><span class=\"TextRun Underlined SCXW206924199 BCX0\" lang=\"NL-NL\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW206924199 BCX0\" data-ccp-charstyle=\"Hyperlink\">CCV seal of approval for pen testing<\/span><\/span><\/a><span class=\"TextRun SCXW206924199 BCX0\" lang=\"NL-NL\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW206924199 BCX0\">.<\/span><\/span><span class=\"EOP SCXW206924199 BCX0\" data-ccp-props=\"{\"201341983\":0,\"335559738\":60,\"335559739\":60,\"335559740\":240}\"> <\/span><\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h3 id=\"elementor-tab-title-2598\" class=\"elementor-tab-title\" data-tab=\"8\" role=\"button\" aria-controls=\"elementor-tab-content-2598\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Are you dealing with a security incident? How NFIR helps<\/a>\n\t\t\t\t\t<\/h3>\n\t\t\t\t\t<div id=\"elementor-tab-content-2598\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"8\" role=\"region\" aria-labelledby=\"elementor-tab-title-2598\"><p>If you are dealing with a <a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\">security incident<\/a>, you can rely on NFIR&#8217;s expertise. We offer a unique approach to finding IT vulnerabilities. Our ethical hackers are well trained and work according to standardized ISO norms to find vulnerabilities in your IT.<\/p>\n<ul>\n<li><a href=\"https:\/\/www.cyber-security-online.nl\/en\/accreditations\/\">NFIR is a Computer Emergency Response Team (CERT)<\/a><\/li>\n<li><a style=\"font-size: 16px; background-color: #ffffff;\" href=\"https:\/\/www.cyber-security-online.nl\/en\/accreditations\/\">NFIR holds ISO-27001 certification. <\/a><\/li>\n<\/ul>\n<p>Whether you have a vulnerability in your infrastructure, need insight into threat vectors or need an ethical hacker to understand how attackers can penetrate, NFIR can help. We perform detailed pen testing that delivers an accurate and understandable report. This provides you with a clear picture of your current security and offers concrete recommendations for improvement. Moreover, you can expect results within days, which means you can take quick action to strengthen your IT security. NFIR&#8217;s help significantly reduces the risk of hacking.<\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-252e0db e-con-full e-flex e-con e-parent\" data-id=\"252e0db\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7ead8f8 elementor-widget elementor-widget-menu-anchor\" data-id=\"7ead8f8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"menu-anchor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-menu-anchor\" id=\"pentest-high-quality\"><\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c7ced7d elementor-widget elementor-widget-template\" data-id=\"c7ced7d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"template.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-template\">\n\t\t\t\t\t<div data-elementor-type=\"container\" data-elementor-id=\"117095\" class=\"elementor elementor-117095 elementor-117091 elementor-117091\" data-elementor-post-type=\"elementor_library\">\n\t\t\t\t<div class=\"elementor-element elementor-element-418e59a8 e-flex e-con-boxed e-con e-parent\" data-id=\"418e59a8\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3937c9a elementor-widget elementor-widget-heading\" data-id=\"3937c9a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">High quality pen testing<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-da2ae28 elementor-widget elementor-widget-heading\" data-id=\"da2ae28\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Certified and quality-oriented pentesters<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-12de74d elementor-widget elementor-widget-text-editor\" data-id=\"12de74d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Pentests are essential to test the technical resilience and effective operation of security. Our pentesters focus on identifying vulnerabilities in systems by deploying various attack techniques. Our skilled and professional pen testers have extensive experience, creativity and up-to-date professional knowledge. The pentesters have completed various <b>relevant training courses <\/b>and hold the following certifications, among others, <a href=\"https:\/\/www.offsec.com\/courses\/pen-200\/\" target=\"_blank\" rel=\"noopener\">OSCP<\/a>, <a href=\"https:\/\/www.offsec.com\/courses\/pen-210\/\" target=\"_blank\" rel=\"noopener\">OSWP<\/a>, <a href=\"https:\/\/www.offsec.com\/courses\/web-300\/\" target=\"_blank\" rel=\"noopener\">OSWE<\/a>, <a href=\"https:\/\/www.offsec.com\/courses\/pen-300\/\" target=\"_blank\" rel=\"noopener\">OSEP<\/a>, <a href=\"https:\/\/academy.hackthebox.com\/preview\/certifications\/htb-certified-penetration-testing-specialist\" target=\"_blank\" rel=\"noopener\">CPTS<\/a>, <a href=\"https:\/\/academy.hackthebox.com\/preview\/certifications\/htb-certified-bug-bounty-hunter\" target=\"_blank\" rel=\"noopener\">CBBH<\/a>, and <a href=\"https:\/\/security.ine.com\/certifications\/ewpt-certification\/\" target=\"_blank\" rel=\"noopener\">eWPT<\/a>.<\/p>\n<h3>Pentesting and the CCV seal of approval:<\/h3>\n<ul>\n<li><span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\">This quality mark, based on NEN-EN-ISO\/IEC standards 17021 and 17065, gives customers the guarantee that the execution of a pen testing assignment by NFIR is carried out in a professional and high-quality manner.<\/span><\/li>\n<li>NFIR possesses since 07-01-2022 <a href=\"https:\/\/hetccv.nl\/bedrijven\/nfir-b-v\/\" target=\"_blank\" rel=\"noopener\"><strong>the CCV quality mark<\/strong><\/a> for Pentesting.  <a href=\"https:\/\/hetccv.nl\/bedrijven\/nfir-b-v\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"alignnone wp-image-116530 size-thumbnail\" title=\"logo ccv nl\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/06\/logo_ccv_nl.svg\" alt=\"logo ccv nl, Center for Crime Prevention and Security, pentest seals of approval.\" width=\"150\" height=\"150\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/\/2024\/06\/logo_ccv_nl.svg 150w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/\/2024\/06\/logo_ccv_nl.svg 300w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/\/2024\/06\/logo_ccv_nl.svg 1024w\" sizes=\"(max-width: 150px) 100vw, 150px\" \/><\/a><\/li>\n<\/ul>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-230fda40 elementor-widget elementor-widget-menu-anchor\" data-id=\"230fda40\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"menu-anchor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-menu-anchor\" id=\"pentestquestions\"><\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-f856d63 dashed-line-top dashed-line-bottom e-flex e-con-boxed e-con e-parent\" data-id=\"f856d63\" data-element_type=\"container\" data-e-type=\"container\" id=\"aanvragen\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-57222a2 elementor-widget elementor-widget-menu-anchor\" data-id=\"57222a2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"menu-anchor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-menu-anchor\" id=\"form-top-testing\"><\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-4713145 e-con-full e-flex e-con e-child\" data-id=\"4713145\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-9f4a39c e-con-full e-flex e-con e-child\" data-id=\"9f4a39c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f7ba772 elementor-widget elementor-widget-heading\" data-id=\"f7ba772\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">I want to pentest my environment(s)!<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9239a3f elementor-widget elementor-widget-text-editor\" data-id=\"9239a3f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul>\n<li>Once you fill out this form, we will contact you immediately to inform you of the possibilities.<\/li>\n<li>We schedule a no-obligation intake with a Technical Lead to coordinate scope components and attack scenarios.<\/li>\n<\/ul>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-64226c0 e-con-full e-flex e-con e-child\" data-id=\"64226c0\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-b497928 nfir-from-bdt-gf nfir-form-wrap elementor-widget elementor-widget-shortcode\" data-id=\"b497928\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\"><script>\nvar gform;gform||(document.addEventListener(\"gform_main_scripts_loaded\",function(){gform.scriptsLoaded=!0}),document.addEventListener(\"gform\/theme\/scripts_loaded\",function(){gform.themeScriptsLoaded=!0}),window.addEventListener(\"DOMContentLoaded\",function(){gform.domLoaded=!0}),gform={domLoaded:!1,scriptsLoaded:!1,themeScriptsLoaded:!1,isFormEditor:()=>\"function\"==typeof InitializeEditor,callIfLoaded:function(o){return!(!gform.domLoaded||!gform.scriptsLoaded||!gform.themeScriptsLoaded&&!gform.isFormEditor()||(gform.isFormEditor()&&console.warn(\"The use of gform.initializeOnLoaded() is deprecated in the form editor context and will be removed in Gravity Forms 3.1.\"),o(),0))},initializeOnLoaded:function(o){gform.callIfLoaded(o)||(document.addEventListener(\"gform_main_scripts_loaded\",()=>{gform.scriptsLoaded=!0,gform.callIfLoaded(o)}),document.addEventListener(\"gform\/theme\/scripts_loaded\",()=>{gform.themeScriptsLoaded=!0,gform.callIfLoaded(o)}),window.addEventListener(\"DOMContentLoaded\",()=>{gform.domLoaded=!0,gform.callIfLoaded(o)}))},hooks:{action:{},filter:{}},addAction:function(o,r,e,t){gform.addHook(\"action\",o,r,e,t)},addFilter:function(o,r,e,t){gform.addHook(\"filter\",o,r,e,t)},doAction:function(o){gform.doHook(\"action\",o,arguments)},applyFilters:function(o){return gform.doHook(\"filter\",o,arguments)},removeAction:function(o,r){gform.removeHook(\"action\",o,r)},removeFilter:function(o,r,e){gform.removeHook(\"filter\",o,r,e)},addHook:function(o,r,e,t,n){null==gform.hooks[o][r]&&(gform.hooks[o][r]=[]);var d=gform.hooks[o][r];null==n&&(n=r+\"_\"+d.length),gform.hooks[o][r].push({tag:n,callable:e,priority:t=null==t?10:t})},doHook:function(r,o,e){var t;if(e=Array.prototype.slice.call(e,1),null!=gform.hooks[r][o]&&((o=gform.hooks[r][o]).sort(function(o,r){return o.priority-r.priority}),o.forEach(function(o){\"function\"!=typeof(t=o.callable)&&(t=window[t]),\"action\"==r?t.apply(null,e):e[0]=t.apply(null,e)})),\"filter\"==r)return e[0]},removeHook:function(o,r,t,n){var e;null!=gform.hooks[o][r]&&(e=(e=gform.hooks[o][r]).filter(function(o,r,e){return!!(null!=n&&n!=o.tag||null!=t&&t!=o.priority)}),gform.hooks[o][r]=e)}});\n<\/script>\n\n                <div class='gf_browser_gecko gform_wrapper gravity-theme gform-theme--no-framework' data-form-theme='gravity-theme' data-form-index='0' id='gform_wrapper_14' style='display:none'>\n                        <div class='gform_heading'>\n\t\t\t\t\t\t\t<p class='gform_required_legend'>&quot;<span class=\"gfield_required gfield_required_asterisk\">*<\/span>&quot; indicates required fields<\/p>\n                        <\/div><form method='post' enctype='multipart\/form-data'  id='gform_14'  action='\/en\/wp-json\/wp\/v2\/pages\/3359' data-formid='14' novalidate><div class='gf_invisible ginput_recaptchav3' data-sitekey='6LfmaGsbAAAAAGsZNz38-fzIwXHnLNIyJu3EFl9r' data-tabindex='0'><input id=\"input_026938a9203c9581d2c6759d1274279e\" class=\"gfield_recaptcha_response\" type=\"hidden\" name=\"input_026938a9203c9581d2c6759d1274279e\" value=\"\"\/><\/div>\n                        <div class='gform-body gform_body'><div id='gform_fields_14' class='gform_fields top_label form_sublabel_below description_below validation_below'><div id=\"field_14_8\" class=\"gfield gfield--type-honeypot gform_validation_container field_sublabel_below gfield--has-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_14_8'>Comments<\/label><div class='ginput_container'><input name='input_8' id='input_14_8' type='text' value='' autocomplete='new-password'\/><\/div><div class='gfield_description' id='gfield_description_14_8'>This field is for validation purposes and should be left unchanged.<\/div><\/div><div id=\"field_14_7\" class=\"gfield gfield--type-text gfield--input-type-text gfield--width-full gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_14_7'>Company name<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_asterisk\">*<\/span><\/span><\/label><div class='ginput_container ginput_container_text'><input name='input_7' id='input_14_7' type='text' value='' class='large'     aria-required=\"true\" aria-invalid=\"false\"   \/><\/div><\/div><fieldset id=\"field_14_1\" class=\"gfield gfield--type-name gfield--input-type-name gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><legend class='gfield_label gform-field-label gfield_label_before_complex' >Name<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_asterisk\">*<\/span><\/span><\/legend><div class='ginput_complex ginput_container ginput_container--name no_prefix has_first_name no_middle_name has_last_name no_suffix gf_name_has_2 ginput_container_name gform-grid-row' id='input_14_1'>\n                            \n                            <span id='input_14_1_3_container' class='name_first gform-grid-col gform-grid-col--size-auto' >\n                                                    <input type='text' name='input_1.3' id='input_14_1_3' value=''   aria-required='true'     \/>\n                                                    <label for='input_14_1_3' class='gform-field-label gform-field-label--type-sub '>First<\/label>\n                                                <\/span>\n                            \n                            <span id='input_14_1_6_container' class='name_last gform-grid-col gform-grid-col--size-auto' >\n                                                    <input type='text' name='input_1.6' id='input_14_1_6' value=''   aria-required='true'     \/>\n                                                    <label for='input_14_1_6' class='gform-field-label gform-field-label--type-sub '>Last<\/label>\n                                                <\/span>\n                            \n                        <\/div><\/fieldset><div id=\"field_14_3\" class=\"gfield gfield--type-phone gfield--input-type-phone gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_14_3'>Telephone number<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_asterisk\">*<\/span><\/span><\/label><div class='ginput_container ginput_container_phone'><input name='input_3' id='input_14_3' type='tel' value='' class='large'   aria-required=\"true\" aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_14_2\" class=\"gfield gfield--type-email gfield--input-type-email gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_14_2'>E-mail address<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_asterisk\">*<\/span><\/span><\/label><div class='ginput_container ginput_container_email'>\n                            <input name='input_2' id='input_14_2' type='email' value='' class='large'    aria-required=\"true\" aria-invalid=\"false\"  \/>\n                        <\/div><\/div><fieldset id=\"field_14_5\" class=\"gfield gfield--type-checkbox gfield--type-choice gfield--input-type-checkbox gf_list_2col_vertical gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><legend class='gfield_label gform-field-label gfield_label_before_complex' >What environment(s) would you like to have pentested?<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_asterisk\">*<\/span><\/span><\/legend><div class='ginput_container ginput_container_checkbox'><div class='gfield_checkbox ' id='input_14_5'><div class='gchoice gchoice_14_5_1'>\n\t\t\t\t\t\t\t\t<input class='gfield-choice-input' name='input_5.1' type='checkbox'  value='Infrastructure'  id='choice_14_5_1'   \/>\n\t\t\t\t\t\t\t\t<label for='choice_14_5_1' id='label_14_5_1' class='gform-field-label gform-field-label--type-inline'>Infrastructure<\/label>\n\t\t\t\t\t\t\t<\/div><div class='gchoice gchoice_14_5_2'>\n\t\t\t\t\t\t\t\t<input class='gfield-choice-input' name='input_5.2' type='checkbox'  value='Web application'  id='choice_14_5_2'   \/>\n\t\t\t\t\t\t\t\t<label for='choice_14_5_2' id='label_14_5_2' class='gform-field-label gform-field-label--type-inline'>Web application<\/label>\n\t\t\t\t\t\t\t<\/div><div class='gchoice gchoice_14_5_3'>\n\t\t\t\t\t\t\t\t<input class='gfield-choice-input' name='input_5.3' type='checkbox'  value='Mobile application'  id='choice_14_5_3'   \/>\n\t\t\t\t\t\t\t\t<label for='choice_14_5_3' id='label_14_5_3' class='gform-field-label gform-field-label--type-inline'>Mobile application<\/label>\n\t\t\t\t\t\t\t<\/div><div class='gchoice gchoice_14_5_4'>\n\t\t\t\t\t\t\t\t<input class='gfield-choice-input' name='input_5.4' type='checkbox'  value='API'  id='choice_14_5_4'   \/>\n\t\t\t\t\t\t\t\t<label for='choice_14_5_4' id='label_14_5_4' class='gform-field-label gform-field-label--type-inline'>API<\/label>\n\t\t\t\t\t\t\t<\/div><div class='gchoice gchoice_14_5_5'>\n\t\t\t\t\t\t\t\t<input class='gfield-choice-input' name='input_5.5' type='checkbox'  value='Operational Technology (OT)'  id='choice_14_5_5'   \/>\n\t\t\t\t\t\t\t\t<label for='choice_14_5_5' id='label_14_5_5' class='gform-field-label gform-field-label--type-inline'>Operational Technology (OT)<\/label>\n\t\t\t\t\t\t\t<\/div><div class='gchoice gchoice_14_5_6'>\n\t\t\t\t\t\t\t\t<input class='gfield-choice-input' name='input_5.6' type='checkbox'  value='DigiD'  id='choice_14_5_6'   \/>\n\t\t\t\t\t\t\t\t<label for='choice_14_5_6' id='label_14_5_6' class='gform-field-label gform-field-label--type-inline'>DigiD<\/label>\n\t\t\t\t\t\t\t<\/div><div class='gchoice gchoice_14_5_7'>\n\t\t\t\t\t\t\t\t<input class='gfield-choice-input' name='input_5.7' type='checkbox'  value='MedMij'  id='choice_14_5_7'   \/>\n\t\t\t\t\t\t\t\t<label for='choice_14_5_7' id='label_14_5_7' class='gform-field-label gform-field-label--type-inline'>MedMij<\/label>\n\t\t\t\t\t\t\t<\/div><div class='gchoice gchoice_14_5_8'>\n\t\t\t\t\t\t\t\t<input class='gfield-choice-input' name='input_5.8' type='checkbox'  value='otherwise' checked='checked' id='choice_14_5_8'   \/>\n\t\t\t\t\t\t\t\t<label for='choice_14_5_8' id='label_14_5_8' class='gform-field-label gform-field-label--type-inline'>Otherwise<\/label>\n\t\t\t\t\t\t\t<\/div><\/div><\/div><\/fieldset><div id=\"field_14_6\" class=\"gfield gfield--type-textarea gfield--input-type-textarea field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_14_6'>Additional Information<\/label><div class='ginput_container ginput_container_textarea'><textarea name='input_6' id='input_14_6' class='textarea medium'    placeholder='For example: I would like general information about NFIR pen testing.'  aria-invalid=\"false\"   rows='10' cols='50'><\/textarea><\/div><\/div><\/div><\/div>\n        <div class='gform-footer gform_footer top_label'> <input type='submit' id='gform_submit_button_14' class='gform_button button' onclick='gform.submission.handleButtonClick(this);' data-submission-type='submit' value='Send'  \/> \n            <input type='hidden' class='gform_hidden' name='gform_submission_method' data-js='gform_submission_method_14' value='postback' \/>\n            <input type='hidden' class='gform_hidden' name='gform_theme' data-js='gform_theme_14' id='gform_theme_14' value='gravity-theme' \/>\n            <input type='hidden' class='gform_hidden' name='gform_style_settings' data-js='gform_style_settings_14' id='gform_style_settings_14' value='[]' \/>\n            <input type='hidden' class='gform_hidden' name='is_submit_14' value='1' \/>\n            <input type='hidden' class='gform_hidden' name='gform_submit' value='14' \/>\n            \n            <input type='hidden' class='gform_hidden' name='gform_currency' data-currency='EUR' value='TedUXoBZto17z9ca\/5CKNqZK1fhAvRFvjjPnCIAJZZ3mzkkGG1k+8VCMDZtEY\/Ik0coUs4hh9L2AzEqdOqo3UgTkWC\/OVgqyoGOdxaUo+5PUrQM=' \/>\n            <input type='hidden' class='gform_hidden' name='gform_unique_id' value='' \/>\n            <input type='hidden' class='gform_hidden' name='state_14' value='WyJbXSIsIjM4ZTJmMmZlY2RkMzM1OGQ5YzcyM2ZkMDVmZTVlZTUwIl0=' \/>\n            <input type='hidden' autocomplete='off' class='gform_hidden' name='gform_target_page_number_14' id='gform_target_page_number_14' value='0' \/>\n            <input type='hidden' autocomplete='off' class='gform_hidden' name='gform_source_page_number_14' id='gform_source_page_number_14' value='1' \/>\n            <input type='hidden' name='gform_field_values' value='' \/>\n            \n        <\/div>\n                        <\/form>\n                        <\/div><script>\ngform.initializeOnLoaded( function() {gformInitSpinner( 14, 'https:\/\/www.cyber-security-online.nl\/wp-content\/plugins\/gravityforms\/images\/spinner.svg', true );jQuery('#gform_ajax_frame_14').on('load',function(){var contents = jQuery(this).contents().find('*').html();var is_postback = contents.indexOf('GF_AJAX_POSTBACK') >= 0;if(!is_postback){return;}var form_content = jQuery(this).contents().find('#gform_wrapper_14');var is_confirmation = jQuery(this).contents().find('#gform_confirmation_wrapper_14').length > 0;var is_redirect = contents.indexOf('gformRedirect(){') >= 0;var is_form = form_content.length > 0 && ! is_redirect && ! is_confirmation;var mt = parseInt(jQuery('html').css('margin-top'), 10) + parseInt(jQuery('body').css('margin-top'), 10) + 100;if(is_form){form_content.find('form').css('opacity', 0);jQuery('#gform_wrapper_14').html(form_content.html());if(form_content.hasClass('gform_validation_error')){jQuery('#gform_wrapper_14').addClass('gform_validation_error');} else {jQuery('#gform_wrapper_14').removeClass('gform_validation_error');}setTimeout( function() { \/* delay the scroll by 50 milliseconds to fix a bug in chrome *\/  }, 50 );if(window['gformInitDatepicker']) {gformInitDatepicker();}if(window['gformInitPriceFields']) {gformInitPriceFields();}var current_page = jQuery('#gform_source_page_number_14').val();gformInitSpinner( 14, 'https:\/\/www.cyber-security-online.nl\/wp-content\/plugins\/gravityforms\/images\/spinner.svg', true );jQuery(document).trigger('gform_page_loaded', [14, current_page]);window['gf_submitting_14'] = false;}else if(!is_redirect){var confirmation_content = jQuery(this).contents().find('.GF_AJAX_POSTBACK').html();if(!confirmation_content){confirmation_content = contents;}jQuery('#gform_wrapper_14').replaceWith(confirmation_content);jQuery(document).trigger('gform_confirmation_loaded', [14]);window['gf_submitting_14'] = false;wp.a11y.speak(jQuery('#gform_confirmation_message_14').text());}else{jQuery('#gform_14').append(contents);if(window['gformRedirect']) {gformRedirect();}}jQuery(document).trigger(\"gform_pre_post_render\", [{ formId: \"14\", currentPage: \"current_page\", abort: function() { this.preventDefault(); } }]);        if (event && event.defaultPrevented) {                return;        }        const gformWrapperDiv = document.getElementById( \"gform_wrapper_14\" );        if ( gformWrapperDiv ) {            const visibilitySpan = document.createElement( \"span\" );            visibilitySpan.id = \"gform_visibility_test_14\";            gformWrapperDiv.insertAdjacentElement( \"afterend\", visibilitySpan );        }        const visibilityTestDiv = document.getElementById( \"gform_visibility_test_14\" );        let postRenderFired = false;        function triggerPostRender() {            if ( postRenderFired ) {                return;            }            postRenderFired = true;            gform.core.triggerPostRenderEvents( 14, current_page );            if ( visibilityTestDiv ) {                visibilityTestDiv.parentNode.removeChild( visibilityTestDiv );            }        }        function debounce( func, wait, immediate ) {            var timeout;            return function() {                var context = this, args = arguments;                var later = function() {                    timeout = null;                    if ( !immediate ) func.apply( context, args );                };                var callNow = immediate && !timeout;                clearTimeout( timeout );                timeout = setTimeout( later, wait );                if ( callNow ) func.apply( context, args );            };        }        const debouncedTriggerPostRender = debounce( function() {            triggerPostRender();        }, 200 );        if ( visibilityTestDiv && visibilityTestDiv.offsetParent === null ) {            const observer = new MutationObserver( ( mutations ) => {                mutations.forEach( ( mutation ) => {                    if ( mutation.type === 'attributes' && visibilityTestDiv.offsetParent !== null ) {                        debouncedTriggerPostRender();                        observer.disconnect();                    }                });            });            observer.observe( document.body, {                attributes: true,                childList: false,                subtree: true,                attributeFilter: [ 'style', 'class' ],            });        } else {            triggerPostRender();        }    } );} );\n<\/script>\n<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d075668 dashed-line e-flex e-con-boxed e-con e-parent\" data-id=\"d075668\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-b914a00 e-con-full e-flex e-con e-child\" data-id=\"b914a00\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e916870 elementor-position-top elementor-widget elementor-widget-image-box\" data-id=\"e916870\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><figure class=\"elementor-image-box-img\"><img decoding=\"async\" width=\"521\" height=\"521\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/gecertificeerde-expertise.png\" class=\"attachment-full size-full wp-image-115438\" alt=\"pentest performed\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/gecertificeerde-expertise.png 521w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/gecertificeerde-expertise-300x300.png 300w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/gecertificeerde-expertise-150x150.png 150w\" sizes=\"(max-width: 521px) 100vw, 521px\" \/><\/figure><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">Certified pentesters<\/h3><p class=\"elementor-image-box-description\">The team consists of certified and experienced Technical Leads and pentesters. Specializing in various environments.  <\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-f4634d4 e-con-full e-flex e-con e-child\" data-id=\"f4634d4\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e509e9f elementor-position-top elementor-widget elementor-widget-image-box\" data-id=\"e509e9f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><figure class=\"elementor-image-box-img\"><img decoding=\"async\" width=\"521\" height=\"521\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/op-maat-gemaakte-aanpak.png\" class=\"attachment-full size-full wp-image-115432\" alt=\"pentest performed\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/op-maat-gemaakte-aanpak.png 521w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/op-maat-gemaakte-aanpak-300x300.png 300w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/op-maat-gemaakte-aanpak-150x150.png 150w\" sizes=\"(max-width: 521px) 100vw, 521px\" \/><\/figure><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">Professional approach<\/h3><p class=\"elementor-image-box-description\">Committed Technical Leads and Project Coordinators ensure high-quality pen testing according to the CCV quality mark.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-b765334 e-con-full e-flex e-con e-child\" data-id=\"b765334\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7e7e0e5 elementor-position-top elementor-widget elementor-widget-image-box\" data-id=\"7e7e0e5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><figure class=\"elementor-image-box-img\"><img decoding=\"async\" width=\"521\" height=\"521\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/uitgebreide-ervaring.png\" class=\"attachment-full size-full wp-image-115434\" alt=\"pentest performed\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/uitgebreide-ervaring.png 521w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/uitgebreide-ervaring-300x300.png 300w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/uitgebreide-ervaring-150x150.png 150w\" sizes=\"(max-width: 521px) 100vw, 521px\" \/><\/figure><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">Extensive experience<\/h3><p class=\"elementor-image-box-description\">Have a pen test performed by a team that performs hundreds of pen tests annually with an average customer satisfaction rating of 8.4<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-6d049b4 e-con-full e-flex e-con e-child\" data-id=\"6d049b4\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a6f99d6 elementor-position-top elementor-widget elementor-widget-image-box\" data-id=\"a6f99d6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><figure class=\"elementor-image-box-img\"><img decoding=\"async\" width=\"521\" height=\"521\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/na-test-ondersteuning.png\" class=\"attachment-full size-full wp-image-115436\" alt=\"pentest performed\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/na-test-ondersteuning.png 521w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/na-test-ondersteuning-300x300.png 300w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2024\/03\/na-test-ondersteuning-150x150.png 150w\" sizes=\"(max-width: 521px) 100vw, 521px\" \/><\/figure><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">Clear and transparent<\/h3><p class=\"elementor-image-box-description\">The pen test report is clear, complete and actionable. We always provide an explanation and are also available to you after the project.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>It is becoming increasingly important for companies and organizations to have pen testing performed on their (web) application, website, IT infrastructure, interfaces (APIs) and\/or mobile [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"_seopress_titles_title":"Pentest: The hows and whys about penetration testing | pentesting","_seopress_titles_desc":"Make your organization more secure through professional pen testing for your (web) application, website, IT infrastructure, APIs and mobile apps.\nDiscover the risks and vulnerabilities of your systems and make targeted security improvements.\nPenetration testing provides essential insight for strengthening your IT security.  ","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"both","_seopress_redirections_param":"","_seopress_redirections_type":301,"_seopress_analysis_target_kw":"pentest","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[{"_seopress_pro_rich_snippets_type":"none"}],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"disabled","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"class_list":["post-3359","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/pages\/3359","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/comments?post=3359"}],"version-history":[{"count":0,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/pages\/3359\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media?parent=3359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}