From the testing team

Blog

How we test, what we keep finding and what a test costs; written between assessments by the people who run them.

More articles

A laptop showing a testing timeline with one orange marker beside a blank planner grid

How often should you have a penetration test?

At least once a year and after every major change is the short answer. The real interval follows how fast your environment changes and how much depends on it. This post sets out what ISO 27001, PCI DSS, DigiD, NIS2 and DORA require, which changes call for a test now rather than next year, and a practical cadence per situation.

Read more
A laptop showing a web application in a canal-house office in Amsterdam

Web application penetration testing in the Netherlands

A web application penetration test bought in the Netherlands has two jobs: prove which vulnerabilities the application has, and produce evidence in the form Dutch law, Dutch norms and Dutch auditors ask for. This post covers what the test examines, which frameworks drive it here, what it costs and how long it takes, what the report must contain, and what to check about the provider.

Read more
Web application penetration testing workspace

Blind SQL injection behind rate limiting: DNS exfiltration

When an injection is blind and the target is rate limited, inference alone crawls to a halt. This is a field note on the technique that gets past both: forcing the database to leak its own data over DNS, one 63-character label at a time.

Read more
Board and security team reviewing NIS2 obligations

NIS2 and penetration testing: insight you can act on

Do your security measures also work in practice? Read how a penetration test helps with NIS2 and which steps you can take to address risks where it matters.

Read more
Mobile application security testing

Mobile application security testing: SAST and DAST

A mobile app is a client you hand to the user and a set of API calls you cannot see. Testing it well takes two views: static analysis of the app itself and dynamic testing of it while it runs. This post covers what each reveals.

Read more
Cloud security review across AWS, Azure and GCP

Cloud misconfigurations in AWS, Azure and GCP

The cloud did not invent new classes of mistake; it made a handful of old ones faster to make and easier to miss. This post covers the misconfigurations that turn up in almost every cloud review, and the fix for each, across AWS, Azure, and GCP.

Read more
Wireless network security assessment

Wireless network assessment in 2026: WPA3 and 6 GHz

Wireless has changed. WPA3, Wi-Fi 6E, and the 6 GHz band moved the goalposts, but the findings that matter are still about downgrade, client trust, and segmentation. This post covers what a wireless assessment looks at now.

Read more
Web and API application security testing

OWASP Top 10 in practice: what Pentrox actually finds

The OWASP Top 10 maps where web and API risk lives, but a list of categories is not the same as what turns up in a real test. This post covers the ones that appear most often, with a plain example and the fix.

Read more
Web and API security testing workspace

API security testing: beyond the web OWASP Top 10

APIs fail differently from web pages. The most common serious findings are about authorisation on individual objects, not the classic injection flaws. This post covers what an API test actually looks for.

Read more
A buyer reviewing penetration test scope and duration with Pentrox

What a penetration test costs and what it delivers

What does a penetration test cost and what do you get for it? See our indicative prices and read how Pentrox helps you understand risks, improve where it matters and build on with confidence.

Read more
Human tester reviewing AI-assisted findings

AI versus human in penetration testing: the Pentrox approach

Artificial intelligence has changed how quickly parts of a penetration test can be done; it has not changed the part that decides whether an assessment is any good, which is human judgment. This post explains where AI helps, where a senior tester is irreplaceable, and how Pentrox combines the two.

Read more
Verifying a remediated finding during a retest

Retesting: how a fix is proven, not assumed

A finding is closed when it has been retested, not when a fix has been deployed. This post explains what a retest checks, the three outcomes it can record, and why the record of verified fixes matters during an audit.

Read more

Ready to Secure Your Environment?

Schedule a free intake call to scope your assessment. Pentrox identifies vulnerabilities in your applications, infrastructure, and cloud environments before attackers do.

Schedule an intake call