# Pentrox > Pentrox B.V. is a Dutch offensive security consultancy based in Amsterdam. It performs penetration tests, red team assessments and compliance-driven security testing for organisations in the Netherlands, Belgium and Luxembourg. Every assessment is led or supervised by senior ethical hackers holding one or more industry-standard certifications such as OSCP, OSCE, OSWE, eWPTX, eMAPT, CPTS, CWES and BSCP; critical findings are escalated immediately; the final report follows within five business days after testing; retesting of remediated findings is included at no additional cost. Findings, reports, retest results and project communication are delivered through the Pentrox Portal at portal.pentrox.nl. Languages: English and Dutch. Pentrox B.V. is a private limited company (besloten vennootschap) incorporated in the Netherlands in 2026 and registered with the Dutch Chamber of Commerce. The registered office is Keizersgracht 241, 1016 EA Amsterdam. Pentrox serves organisations that need evidence that their security measures work: for NIS2 (Cyberbeveiligingswet), ISO 27001, DigiD, PCI-DSS, or their own risk management. Typical clients are organisations with web applications, mobile applications and cloud infrastructure, organisations in regulated sectors such as finance, healthcare, government and critical infrastructure, Dutch government bodies that use DigiD, and security-mature organisations that want a realistic adversary simulation. Assessments are performed from the Netherlands over authorised remote access. On-site work, including mystery guest assessments and hardware testing, is available throughout the Benelux. Project communication is in English or Dutch. Reports are delivered in English by default; a Dutch executive summary can be requested during scoping at no additional cost. Pentrox does not use client names in marketing material and shares references only with prior written consent. - [Home](https://www.pentrox.nl/en/): penetration testing, red teaming and compliance-driven security testing by senior ethical hackers, with the report within five business days and a retest included. ## Why Pentrox Each point below describes a mechanism that applies to every Pentrox assessment, regardless of scope. - **Senior testers do the work themselves.** Every assessment is performed or supervised by senior penetration testers holding one or more industry-standard certifications such as OSCP, OSCE, OSWE, eWPTX, eMAPT, CPTS, CWES and BSCP, and the name on the report is the person who tested the systems. - **Direct line to the tester.** There is no account manager between the client and the ethical hacker; questions are raised in the project conversation inside the Pentrox Portal, with replies, mentions, file attachments and references to specific findings. - **Findings are published during testing.** A validated finding appears in the Pentrox Portal with severity, affected component, evidence and remediation guidance before the report exists, so remediation can start before testing ends. - **Critical findings are escalated immediately.** A critical or blocking finding is communicated the moment it is confirmed, by phone, e-mail or portal alert as agreed during scoping. When a pre-existing compromise or an active attacker is found, testing is paused until the client instructs otherwise. - **Final report within five business days.** The report is delivered within five business days after testing completes, after an internal quality review. - **Retesting is included as standard.** Remediated findings are retested at no additional cost within 90 days of report delivery. Each finding receives its own result (resolved, partially resolved or still open) and further retest cycles can be requested until every finding is closed. - **The Pentrox Portal is included with every assessment.** There is no per-user licence, no cap on the number of users and no expiry on access; project data, findings and reports remain available until the client asks for removal. - **Every finding is manually validated.** Automated scanners such as Nessus and ScoutSuite are the starting point; a senior tester confirms exploitability, removes false positives and chains findings into realistic attack paths. - **Every report passes internal review.** Findings and reports pass an internal peer review by a second tester before they are published to the client. - **One report for two audiences.** Findings are ranked by business impact and not only by their severity score; the executive summary serves management, and the detailed findings give developers evidence, reproduction steps and remediation guidance. - **Findings are mapped to the standard.** Compliance assessments map every finding to NIS2 Article 21 measures (d), (e) and (f), ISO/IEC 27001:2022 Annex A control A.8.29, PCI DSS v4.0 Requirement 11.4 or the Logius DigiD Normenkader, so the report serves as audit evidence. - **Assessment data stays in the European Union.** The Pentrox Portal runs on a dedicated virtual private server in a datacenter in the European Union, assessment work is not offshored, and the only third-country sub-processor is Cloudflare (United States, EU-U.S. Data Privacy Framework), which carries Portal traffic encrypted in transit and does not store it. - **Two-factor authentication on every portal account.** Every user enrols an authenticator app or a passkey (FIDO2) before the first sign-in; role-based access limits each user to the projects they are assigned to. - **Screened personnel.** All Pentrox employees undergo PES (Personnel Screening) background checks at the start of employment; contractor use is limited and contractors are bound by the same confidentiality obligations and code of ethics. - **Fixed price after scoping.** Pricing is based on the estimated number of testing days determined during scoping; a fixed-price quotation follows, and every enquiry receives a response within one business day. - **NDA and DPA before testing.** A mutual non-disclosure agreement is available before scoping information is exchanged, and a Data Processing Agreement is signed before any assessment begins. - **Non-destructive testing.** All testing is controlled and non-destructive, preferably in a non-production environment; production testing is agreed explicitly during scoping with planned testing windows. - **Honest about certifications.** No organisational certificate has been issued yet; Pentrox B.V. was incorporated recently. Its way of working is fully aligned with every requirement of the CCV Keurmerk Pentesten, and that certification is in progress. Team certifications (OSCP, OSCE, OSWE, eWPTX) are personal and are not presented as a substitute. - **Written code of ethics.** Pentrox never deploys ransomware, wipers or destructive payloads, never performs denial-of-service testing without written authorisation, never exfiltrates real personal or payment data beyond the minimum evidence for a finding, and never touches systems outside the signed scope. ## Services - [All services](https://www.pentrox.nl/en/services/): overview of every Pentrox service, from web application testing to red teaming and compliance testing. ### Penetration testing - [Penetration testing services](https://www.pentrox.nl/en/pentesting/): hub page; senior ethical hackers test applications, infrastructure and cloud, with the report within five business days and retesting included. - [Web application and API penetration testing](https://www.pentrox.nl/en/web-api-penetration-testing/): manual testing of authentication, session handling, data validation, business logic and trust boundaries, beyond the OWASP Top 10; aligned with OWASP WSTG, the API Security Top 10 and ASVS. - [Infrastructure penetration testing](https://www.pentrox.nl/en/infrastructure-penetration-testing/): external perimeter, internal network and Active Directory, tested the way an attacker moves; Nessus scanning combined with manual exploitation, privilege escalation and lateral movement (PTES, NIST SP 800-115, MITRE ATT&CK). - [Cloud security review](https://www.pentrox.nl/en/cloud-security-review/): configuration and identity review of AWS, Azure or GCP covering IAM, storage, network controls, encryption and audit logging; ScoutSuite scanning combined with manual review (CIS Benchmarks, NIST SP 800-53, CSA CCM). - [Azure and Entra ID penetration testing](https://www.pentrox.nl/en/azure-pentest/): Entra ID conditional access, roles, app registrations, Azure resources and Microsoft 365, tested from the position of an external attacker and of a compromised user; Microsoft permits customers to test their own tenant without prior approval. - [Mobile application security](https://www.pentrox.nl/en/mobile-application-security/): iOS and Android applications plus the backend API; secure storage, inter-process communication, certificate pinning and runtime manipulation tested through reverse engineering, static analysis and dynamic testing (OWASP MSTG, MASVS). - [Source code review](https://www.pentrox.nl/en/source-code-review/): manual review of authentication logic, access control, dependencies and configuration handling for Java, C#, JavaScript, Python, PHP and Go, combined with a penetration test of the running application (OWASP Code Review Guide, ASVS, CWE Top 25). - [AI and LLM penetration testing](https://www.pentrox.nl/en/ai-llm-pentest/): chatbots, copilots and agents built on large language models; prompt injection, data leakage, tool abuse and the application layer around the model, mapped to the OWASP Top 10 for LLM Applications; report in 5 business days, retest included. - [Hardware security testing](https://www.pentrox.nl/en/hardware-security-testing/): firmware extraction, debug interfaces (JTAG, UART, USB), bootloader integrity, wireless protocols and physical access on embedded and IoT devices (OWASP IoT Top 10, NIST SP 800-183). ### Compliance and standards - [Compliance penetration testing](https://www.pentrox.nl/en/compliance-standards/): hub page; evidence for NIS2, ISO 27001, DigiD and PCI-DSS, with findings mapped to the requirements of the standard and reports structured for auditors and certification bodies. - [NIS2 penetration testing](https://www.pentrox.nl/en/nis2-pentest/): evidence for the duty of care in the Cyberbeveiligingswet, in force since 15 August 2026; findings mapped to NIS2 Article 21 measures (d) supply chain security, (e) secure development and vulnerability handling, and (f) assessing the effectiveness of measures; a retest within 90 days is included. - [ISO 27001 penetration testing](https://www.pentrox.nl/en/iso27001-pentest/): evidence for Annex A control A.8.29 of ISO/IEC 27001:2022, scoped to the certification boundary; findings mapped to Annex A controls for certification body review. - [DigiD penetration testing](https://www.pentrox.nl/en/digid-pentest/): the annual DigiD security assessment required by Logius, tested against the DigiD Normenkader and the BIO (Baseline Informatiebeveiliging Overheid); report in the format required for Logius compliance reporting. - [PCI-DSS penetration testing](https://www.pentrox.nl/en/pci-dss-pentest/): PCI DSS v4.0 Requirement 11.4 testing of the cardholder data environment; segmentation controls, access restrictions, encryption and key management validated, with reporting structured for QSA review. - [NEN 7510 penetration testing](https://www.pentrox.nl/en/nen7510-pentest/): healthcare providers and their ICT suppliers; access to patient records, NEN 7513 logging, data exchange (NEN 7512) and infrastructure tested against the controls of NEN 7510; report in 5 business days, retest included. ### Advanced testing - [Advanced testing](https://www.pentrox.nl/en/advanced-testing/): hub page; red teaming, scenario-based pentests, phishing simulation and mystery guest assessments test detection and response against a realistic attack. - [Red teaming](https://www.pentrox.nl/en/red-teaming/): objective-based, multi-vector adversary simulation across network, application, social engineering and physical access, testing detection and response of the whole organisation (MITRE ATT&CK, PTES, NIST SP 800-115). - [Scenario-based pentest](https://www.pentrox.nl/en/scenario-based-pentest/): a predefined attack scenario agreed with the client and executed covertly by senior red team specialists; the Security Operations Centre is not informed unless agreed otherwise, so detection and response are evaluated under real conditions. - [Phishing simulation](https://www.pentrox.nl/en/phishing-simulation/): controlled e-mail campaigns with organisation-specific pretexts; click rates, credential submission and reporting behaviour are measured and reported within five business days after the campaign. - [Mystery guest](https://www.pentrox.nl/en/mystery-guest/): authorised physical security assessment in which senior consultants with PES clearance attempt to enter premises using tailgating, social engineering and physical weaknesses, within agreed boundaries and with evidence for every step. ### Continuous testing - [Pentest as a Service (PTaaS)](https://www.pentrox.nl/en/pentest-as-a-service/): a long-term subscription with an annual allocation of testing days; senior ethical hackers test new features and changes before they go live, findings are published in real time in the Pentrox Portal, and retesting is part of every cycle. PTaaS is the only Pentrox service sold as a subscription. Each subscription starts with an onboarding phase of 10 to 15 testing days, counted inside the yearly budget, in which the environment is scoped, the asset surface is mapped and an initial sweep is performed. Indicative yearly bands: Focused, 10 to 20 testing days per year for a single web application or API; Core, 20 to 30 testing days per year for multi-module SaaS platforms or a combined web and mobile surface; Extensive, 30 or more testing days per year for enterprise environments with cloud infrastructure or continuous-testing evidence obligations under PCI-DSS v4, NIS2 Article 21 or ISO 27001 Annex A. Compared with an annual pentest, PTaaS keeps the same tester on the environment and tests code as it ships instead of once a year. ## Indicative testing days per service Illustrative bands from the service pages, in testing days, for a small scope, a core scope and a complex scope. Exact duration is confirmed in the statement of work. Pentrox does not publish prices; every quotation follows a scoping call. - Web and API penetration testing: 3 to 4 (single application, one authentication flow); 4 to 7 (multiple roles plus a REST or GraphQL API); 7 or more (microservices, two or more API versions, complex OAuth). - Cloud security review: 3 to 4 (single account, simple IAM); 4 to 7 (multi-account with infrastructure-as-code review); 7 or more (multi-cloud, extensive IAM, serverless, containers). - Mobile application security: 3 to 4 (one platform, limited backend); 4 to 7 (both platforms, moderate backend); 7 or more (both platforms, extensive backend, anti-tamper, multiple roles). - Source code review: 3 to 4 (one language, focused modules); 4 to 6 (multi-module with RBAC, API integrations and a combined pentest); 6 or more (large multi-language codebase, complex authentication). - Infrastructure penetration testing: 4 to 5 (external perimeter only); 5 to 10 (external and internal with Active Directory and segmentation); 10 or more (multiple domains, forest trusts, distributed segments). - Hardware security testing: 4 to 5 (single device, no wireless); 5 to 8 (firmware extraction, bootloader, wireless); 8 or more (multiple variants, side-channel, supply chain). - DigiD pentest: 4 to 5 (one DigiD connection); 5 to 8 (two or more DigiD services plus infrastructure); 8 or more (distributed DigiD, citizen data flows). - PCI-DSS pentest: 3 to 5 (one payment application, one CDE zone); 5 to 8 (two or more applications or CDE zones with segmentation); 8 or more (large CDE, third-party integrations). - ISO 27001 pentest: 4 to 6 (one application in the ISMS boundary); 6 to 10 (two or more applications, network and access control); 10 or more (large ISMS, distributed systems, broad Annex A). - NIS2 pentest: 5 to 7 (one critical system, no supply chain); 7 to 12 (two or more critical systems with segmentation); 12 or more (large infrastructure, supply chain, incident-detection validation). - Mystery guest: 2 to 3 (one location, one or two scenarios); 3 to 5 (one location with three or more scenarios, or two locations); 5 or more (three or more locations). - Phishing simulation: 3 to 5 (single wave, one group); 5 to 10 (two or three waves, full organisation); 10 or more (multi-wave spear phishing with credential harvesting and reporting-behaviour analysis). - Scenario-based pentest: 5 to 7 (single scenario, one vector); 7 to 15 (multi-vector with detection and response across two or more entry points); 15 or more (physical, social and technical across a large environment). - Red teaming: 15 to 20 (defined objective, two vectors, bounded environment); 20 to 35 (multi-vector with social engineering, detection evaluation and persistence); 35 or more (full-scope adversary simulation with extended persistence and evasion). For mystery guest, phishing simulation, scenario-based pentests and red teaming, a repeat or follow-up exercise is available separately, with scope and timeline agreed separately. For all other services the retest is included. ## How an assessment works - [Process](https://www.pentrox.nl/en/process/): the five steps of a Pentrox assessment, from scope to retest, tracked in the Pentrox Portal. 1. **Scope and intake.** Objectives, targets, environments, risk appetite and compliance framework are fixed in one focused session; test accounts, source code availability and the testing approach (white, grey or black box) are agreed. Scoping starts with a short intake conversation or an intake checklist in the Pentrox Portal. 2. **Planning and preparation.** Test windows are agreed around the release calendar, the methodology is confirmed against OWASP, PTES and NIST, escalation paths and named contacts on both sides are recorded, and the portal lists the required items the client must supply before testing starts. 3. **Assessment and validation.** Senior testers combine tailored automated scanning, manual validation and hands-on exploitation within the agreed methodology. Findings are published in the portal as they are validated; critical findings are escalated immediately; all activity is non-destructive. 4. **Reporting and quality assurance.** Findings are internally validated and written up for both technical teams and executive leadership. Every report passes an internal quality review before release. The final report is delivered within five business days after testing completes. 5. **Findings meeting and retest.** Pentrox and the client align on priorities and remediation approach. Once fixes are deployed, the client flags findings in the portal, uploads evidence, and an assigned retest pentester and reviewer verify each fix. A retest management report closes the audit loop. ## What the report contains Every Pentrox report has five sections, written for both management and developers: - **Executive summary.** Objective, scope and approach, with findings grouped by severity and business impact and clear remediation priorities. - **Vulnerability overview.** All findings categorised by type and severity, with status indicators (open, fixed, retested) to support remediation planning. - **Technical conclusion.** Overall security posture based on severity, patterns and underlying control gaps, with recommendations that go beyond individual fixes. - **Assessment strategy and scope.** Goals, assessed environments, testing approach (for example white box) and scope boundaries, so findings are interpreted in context. - **Detailed findings.** Each vulnerability with description, affected component, evidence, reproduction steps, severity rating (OWASP risk rating; CVSS in compliance assessments) with likelihood and impact, and remediation guidance. Four report types are published to the portal report library: the initial report, a condensed management report for executive and board-level readers, the retest report, and the retest management report. Reports are delivered in English by default; a Dutch executive summary is available on request at no additional cost. A sample redacted report is available during vendor evaluation. - [Sample penetration test report](https://www.pentrox.nl/en/sample-penetration-test-report/): what a Pentrox report contains, how to read a finding and how to request an anonymised sample report. ## The Pentrox Portal - [Pentrox Portal](https://www.pentrox.nl/en/portal/): the client platform at portal.pentrox.nl where findings, reports, retests and project communication are managed from the first day of testing through retest completion. - **Findings dashboard.** Total, open, resolved and accepted-risk findings at a glance; severity breakdown (critical, high, medium, low, informational); monthly trend data; a side-by-side comparison across projects; and one cross-project list of every finding from every assessment. - **Findings during testing.** Published findings appear immediately with description, severity, affected component, evidence and remediation guidance. Status is tracked through the full lifecycle: open, partially resolved, resolved, accepted risk or false positive. - **Remediation plan per finding.** Each finding carries a status (planned, in progress, blocked or done), an optional target date, a ticket reference such as a Jira issue key, and notes, visible to both teams. - **Project lifecycle.** Six visible stages, from Pending to Completed, with automatic notifications on status changes, new reports and new findings. - **Multi-cycle retest workflow.** Flag remediated findings, request a retest, Pentrox assigns a retest pentester and reviewer, each finding receives a verified result, and further cycles can be requested until all findings are addressed. - **Report library.** Initial, management, retest and retest management reports available for download the moment they are published; historical reports stay accessible. - **Accepted-risk decisions.** A finding can be formally proposed as accepted risk; the decision is approved or rejected in the portal and recorded, giving auditors a documented trail. - **Project conversation.** One thread per assessment shared by the client team and the testers: messages, replies, mentions, file attachments, references to findings and the status history of the assessment. - **Required items and document exchange.** The portal lists what the client must supply before testing; credentials, URLs, source code, documentation and remediation evidence are exchanged in the portal rather than by e-mail, and every upload is scanned for malware. - **Client document library.** Quotation, NDA, statement of work, service agreement, data processing agreement and other governing documents are available for download by client administrators. - **Team and access.** Client administrators add and remove their own users and decide who sees which project; every user enrols in two-factor authentication before the first sign-in. - **Portal security.** Mandatory two-factor authentication (authenticator app or FIDO2 passkey), role-based access control tested against IDOR and privilege escalation, CSRF protection, Content Security Policy headers, TLS in transit, encrypted storage volumes, daily backups and audit logging of authentication events, privileged actions and finding lifecycle changes. The portal undergoes the same type of assessment Pentrox performs for clients. ## Testing approaches - [Black box, grey box and white box testing](https://www.pentrox.nl/en/black-box-grey-box-white-box-testing/): the difference in prior knowledge and what each approach delivers. White box gives the tester source code, architecture documentation and credentials and delivers the deepest coverage; it is used for source code reviews, cloud configuration reviews and compliance assessments. Grey box gives limited information such as user credentials and simulates a compromised insider; it is the most common choice for web application and infrastructure testing. Black box starts with no prior knowledge and simulates an external attacker; it is used for external infrastructure assessments, red teaming and scenario-based pentests. ## Trust and procurement - [Trust and procurement](https://www.pentrox.nl/en/trust/): the facts most often requested on a supplier-risk questionnaire; legal identity, certifications, insurance, data handling, incident notification and code of ethics. - [FAQ](https://www.pentrox.nl/en/faq/): answers on cost, lead time, reporting, retesting, tester screening and what happens on a critical finding. - [About Pentrox](https://www.pentrox.nl/en/about/): the team, methodology and technical domains of Pentrox. - [Our Hackers](https://www.pentrox.nl/en/hackers/): the testers behind the assessments, by codename, with their role and certifications; no names or photographs are published. - **Legal identity.** Pentrox B.V., besloten vennootschap, registered with the Kamer van Koophandel, registered office Keizersgracht 241, 1016 EA Amsterdam; contracts, invoices and data processing agreements are executed by Pentrox B.V. - **Methodology alignment.** OWASP Top 10 and OWASP ASVS for application testing, PTES for structured test execution, NIST SP 800-115 for technical assessment methodology, MITRE ATT&CK for adversary emulation; compliance assessments follow ISO/IEC 27001 Annex A, PCI-DSS v4, NIS2 Article 21 or the DigiD assurance framework. Methodology alignment is not an independent audit and Pentrox states this explicitly. - **Insurance.** Professional indemnity and public liability insurance with a Dutch or EU-based carrier, renewed annually; the carrier, limit, liability cap and certificate are shared on request under NDA. - **Data handling.** Pentrox acts as data processor under the GDPR for assessment data; a Data Processing Agreement is signed before any assessment; assessment data is stored in the Pentrox Portal in a datacenter in the European Union and only within the European Economic Area (EEA), with Cloudflare (United States, EU-U.S. Data Privacy Framework) carrying Portal traffic in transit; data remains available to the client indefinitely and is removed on written request; backups run daily. - **Incident notification.** Escalation channel, named contacts on both sides and the out-of-hours path are recorded in the kickoff document; critical findings are escalated immediately through that channel; specific service levels are set in the statement of work. - **Personnel vetting.** PES (Personnel Screening) checks for all employees; clients that require AIVD screening or DigiD-specific clearance should raise it during scoping so that suitable staff can be assigned or the project declined. - **Procurement pack.** Available during vendor evaluation: a completed vendor-risk questionnaire in the client template, certificate of insurance, framework agreement and DPA for review, information security policy summary, sub-processor list, sample redacted report, and the code of ethics. Requests go to info@pentrox.nl with the subject "Procurement pack". - **Responsible disclosure.** Pentrox does not run a paid bug bounty programme; confirmed and fixed findings in Pentrox systems are credited publicly on the responsible disclosure page. ## Pricing and lead time Pentrox does not publish list prices. Pricing is based on the estimated number of testing days, determined during scoping from the size and complexity of the target, the number of user roles and features, the testing approach and any compliance requirements. A fixed-price quotation follows the scoping conversation. Every enquiry receives a response within one business day, and straightforward assessments can often be planned within one to two weeks. Travel costs for on-site work are quoted in the proposal and billed at cost. ## Frequently asked questions - **What is a penetration test?** A controlled security assessment in which ethical hackers attempt to exploit vulnerabilities before malicious actors can, to identify real attack paths, assess business impact and give actionable guidance. - **How is Pentrox different from a vulnerability scanner?** Scanners identify known patterns but cannot reason about business logic, chain vulnerabilities or confirm exploitability; Pentrox uses scanners as a starting point and follows with hands-on manual testing in which every finding is validated. - **Is a penetration test mandatory under NIS2?** Neither NIS2 nor the Cyberbeveiligingswet names a penetration test as mandatory, but Article 21 measure (f) requires an organisation to show that its measures work; the NCSC guideline of 17 July 2025 names penetration tests, vulnerability assessments and code review as the ways to test. There is no official NIS2 certificate. - **Does Pentrox test in production?** Pentrox prefers non-production environments; where production testing is required it is agreed explicitly during scoping with planned testing windows, and all testing remains non-destructive. - **What systems can Pentrox test?** Web applications, APIs, mobile applications (iOS and Android), internal and external network infrastructure, cloud platforms (AWS, Azure, GCP), Microsoft Entra ID and Microsoft 365, source code, embedded devices and IoT systems, plus physical premises and employees through mystery guest and phishing assessments. - **Which certifications does the team hold?** Industry-standard certifications such as OSCP, OSCE, OSWE, eWPTX, eMAPT, CPTS, CWES and BSCP, held by individual team members; every assessment is executed or supervised by senior penetration testers, and all employees are PES screened. - **How many retest cycles are covered?** Retesting of remediated findings is included with every assessment; if findings remain open after the first retest, additional cycles can be requested through the portal. - **Where is data stored?** In the Pentrox Portal, hosted on a dedicated virtual private server in a datacenter in the European Union; assessment data is stored only within the European Economic Area (EEA), and Portal traffic passes through Cloudflare (United States, EU-U.S. Data Privacy Framework) in transit. ## Glossary - [Penetration testing glossary](https://www.pentrox.nl/en/glossary/): short, factual definitions from OSINT to XSS, with what each term means in a penetration test and which service it belongs to. - [What is a penetration test?](https://www.pentrox.nl/en/what-is-a-penetration-test/): a controlled attack by ethical hackers that finds and proves vulnerabilities; how the test runs and what it delivers. - [Vulnerability scan vs penetration test](https://www.pentrox.nl/en/vulnerability-scan-vs-penetration-test/): a scan finds known weaknesses automatically; a pentest proves what an attacker can do with them. - [What is a retest?](https://www.pentrox.nl/en/what-is-a-retest/): verification that a remediated finding is really fixed; included at Pentrox within 90 days of the report, with results recorded per finding. - [What is PTaaS?](https://www.pentrox.nl/en/what-is-ptaas/): continuous penetration testing on a subscription with an annual allocation of testing days. - [What is red teaming?](https://www.pentrox.nl/en/what-is-red-teaming/): an objective-based attack simulation that tests detection and response of the whole organisation; TIBER-EU and MITRE ATT&CK. - [What is phishing?](https://www.pentrox.nl/en/what-is-phishing/): a social engineering attack by e-mail, SMS, phone or QR code; the types and what a simulation measures. - [What is social engineering?](https://www.pentrox.nl/en/what-is-social-engineering/): manipulation of people instead of systems, through phishing, pretexting, tailgating or baiting. - [What is OSINT?](https://www.pentrox.nl/en/what-is-osint/): open source intelligence from DNS, certificates, code repositories and breach data; how attackers and pentesters use it. - [What is security awareness?](https://www.pentrox.nl/en/what-is-security-awareness/): the knowledge and behaviour of employees towards threats such as phishing, and what NIS2 Article 21 requires. - [What is CVSS?](https://www.pentrox.nl/en/what-is-cvss/): the Common Vulnerability Scoring System scores a vulnerability from 0 to 10; the severity bands and the role in a pentest report. - [What is XSS?](https://www.pentrox.nl/en/what-is-xss/): cross-site scripting lets an attacker run scripts in another user's browser; the three types, the impact and the prevention. - [What is IDOR?](https://www.pentrox.nl/en/what-is-idor/): with an insecure direct object reference a user reaches another user's data by changing an identifier. - [What is a backdoor?](https://www.pentrox.nl/en/what-is-a-backdoor/): a hidden access path that bypasses normal authentication, and how a pentest finds it. - [What is a business continuity plan?](https://www.pentrox.nl/en/what-is-a-business-continuity-plan/): a BCP keeps critical processes running during and after an incident; a NIS2 Article 21 measure alongside a pentest. - [What is a penetration test report?](https://www.pentrox.nl/en/what-is-a-penetration-test-report/): what the report contains, how to recognise a good one and how it is used for remediation, the retest and an audit. - [What is an ethical hacker?](https://www.pentrox.nl/en/what-is-an-ethical-hacker/): a specialist who breaks in with written permission to find and report vulnerabilities; the difference with a criminal and with a scanner. - [What is a CVE?](https://www.pentrox.nl/en/what-is-cve/): a unique identifier for a publicly known vulnerability; how it relates to CVSS and CWE and how testers verify a CVE instead of reporting a version number. - [What is a zero-day?](https://www.pentrox.nl/en/what-is-a-zero-day/): a vulnerability unknown to the vendor, so no patch exists; why n-days cause most breaches and how to limit the damage. - [What is SQL injection?](https://www.pentrox.nl/en/what-is-sql-injection/): input executed as part of a database query; in-band, blind and out-of-band variants and prevention with prepared statements. - [What is the OWASP Top 10?](https://www.pentrox.nl/en/what-is-the-owasp-top-10/): the ten most critical web application risks, what the list is and is not, and how a penetration test uses it. - [What is DORA?](https://www.pentrox.nl/en/what-is-dora/): the Digital Operational Resilience Act for financial entities and their ICT providers; yearly testing of critical systems and threat-led testing every three years. - [What is NEN 7510?](https://www.pentrox.nl/en/what-is-nen-7510/): the Dutch healthcare information security standard, how it relates to NEN 7512, NEN 7513 and ISO 27001, and where a penetration test fits. - [What is MFA?](https://www.pentrox.nl/en/what-is-mfa/): multi-factor authentication, which forms are strong, how it is bypassed and how a penetration test checks the gaps. - [What is cloud security?](https://www.pentrox.nl/en/what-is-cloud-security/): shared responsibility, the six configuration mistakes that cause most cloud incidents, and what a cloud security review checks. - [What is a vulnerability scan?](https://www.pentrox.nl/en/what-is-a-vulnerability-scan/): what an automated scan finds and misses, how often to scan, and when a penetration test is needed. - [What is ransomware?](https://www.pentrox.nl/en/what-is-ransomware/): how an attack unfolds from phishing to encryption, why backups alone are not enough and how a penetration test exposes the attack path. ## Blog - [Blog](https://www.pentrox.nl/en/blog/): buyer guides and technical notes on penetration testing, NIS2, reporting and retesting. - [What a penetration test costs and what it delivers](https://www.pentrox.nl/en/blog/what-a-penetration-test-costs/): indicative prices per assessment, what sets the price and what is included as standard. - [How to choose your ethical hackers](https://www.pentrox.nl/en/blog/how-to-choose-your-ethical-hackers/): seven questions that show who will test the systems and how senior they are. - [What to expect during your first penetration test](https://www.pentrox.nl/en/blog/what-to-expect-first-penetration-test/): the five stages from scoping to retest and what each asks of the client team. - [How often should you have a penetration test?](https://www.pentrox.nl/en/blog/how-often-should-you-pentest/): at least yearly and after every major change; what ISO 27001, PCI DSS, DigiD, NIS2 and DORA require and a practical cadence per situation. - [Why the report is the real deliverable](https://www.pentrox.nl/en/blog/why-the-report-is-the-real-deliverable/): the report must serve the board and the developer alike, with reproduction steps a retest can follow. - [Retesting: how a fix is proven, not assumed](https://www.pentrox.nl/en/blog/retesting-how-a-fix-is-proven/): what a retest checks, the three outcomes it records and how a finding is formally closed. - [NIS2 and penetration testing: insight you can act on](https://www.pentrox.nl/en/blog/nis2-and-penetration-testing/): what the Cyberbeveiligingswet asks since 15 August 2026, what a pentest makes clear and three steps to move forward. - [AI versus human in penetration testing](https://www.pentrox.nl/en/blog/ai-versus-human-penetration-testing/): where AI helps, where senior human judgement is irreplaceable, and how Pentrox combines both. - [OWASP Top 10 in practice](https://www.pentrox.nl/en/blog/owasp-top-10-in-practice/): the web and API weaknesses that turn up most often in real penetration tests, with an example and the fix for each. - [API security testing beyond the OWASP Top 10](https://www.pentrox.nl/en/blog/api-security-testing-beyond-owasp-top-10/): BOLA, broken authentication, excessive data exposure and resource limits, with the fix for each. - [Mobile application security testing: SAST and DAST](https://www.pentrox.nl/en/blog/mobile-application-security-testing/): what static and dynamic testing reveal, from hardcoded keys to traffic to the API. - [Cloud misconfigurations in AWS, Azure and GCP](https://www.pentrox.nl/en/blog/cloud-misconfigurations-that-keep-appearing/): public storage, over-broad IAM, exposed metadata and weak logging across AWS, Azure and GCP. - [Wireless network assessment in 2026](https://www.pentrox.nl/en/blog/wireless-network-assessment-in-2026/): WPA3, Wi-Fi 6E and 6 GHz, and the findings that still matter. - [Windows enumeration in 2026](https://www.pentrox.nl/en/blog/windows-enumeration-in-2026/): local host, Active Directory and Entra ID enumeration, living-off-the-land techniques and what defenders can detect. - [File transfer during an assessment](https://www.pentrox.nl/en/blog/file-transfer-during-an-assessment/): common Windows and Linux methods, cloud paths, and what defenders and EDR see. - [Blind SQL injection behind rate limiting: DNS exfiltration](https://www.pentrox.nl/en/blog/dns-exfiltration-blind-sql-injection/): out-of-band DNS exfiltration when inference is throttled, the cookie sink, LOAD_FILE over a UNC path and the controls that stop it. - [Web application penetration testing in the Netherlands](https://www.pentrox.nl/en/blog/web-application-penetration-testing-netherlands/): what the test covers, the Dutch frameworks that require it (Cyberbeveiligingswet, AVG, DigiD, PCI-DSS, ISO 27001), indicative cost and duration, and what the report must contain for a Dutch auditor. ## Dutch pages - [Home (Nederlands)](https://www.pentrox.nl/nl/): Pentrox voert pentesten uit op applicaties, infrastructuur en cloud; senior ethical hackers, rapport binnen 5 werkdagen en een hertest inbegrepen. - [Alle diensten](https://www.pentrox.nl/nl/services/): overzicht van alle pentestdiensten. - [Pentest laten uitvoeren](https://www.pentrox.nl/nl/pentesting/): hub voor penetratietesten door senior ethical hackers. - [Webapplicatie-pentest en API-pentest](https://www.pentrox.nl/nl/web-api-penetration-testing/) - [Infrastructuur-pentest (netwerk-pentest)](https://www.pentrox.nl/nl/infrastructure-penetration-testing/) - [Cloud-pentest en cloud security review](https://www.pentrox.nl/nl/cloud-security-review/) - [Azure-pentest en Entra ID-pentest](https://www.pentrox.nl/nl/azure-pentest/) - [Pentest voor mobiele apps](https://www.pentrox.nl/nl/mobile-application-security/) - [Broncodereview](https://www.pentrox.nl/nl/source-code-review/) - [AI-pentest en LLM-pentest](https://www.pentrox.nl/nl/ai-llm-pentest/): chatbots, copilots en agents; prompt injection, datalekken en misbruik van tools, gekoppeld aan de OWASP Top 10 for LLM Applications. - [Hardware-pentest en IoT-pentest](https://www.pentrox.nl/nl/hardware-security-testing/) - [Pentest voor compliance](https://www.pentrox.nl/nl/compliance-standaarden/): hub voor NIS2, ISO 27001, DigiD en PCI-DSS. - [NIS2-pentest](https://www.pentrox.nl/nl/nis2-pentest/): bewijs voor de zorgplicht van de Cyberbeveiligingswet, bevindingen gekoppeld aan artikel 21. - [ISO 27001-pentest](https://www.pentrox.nl/nl/iso27001-pentest/) - [DigiD-pentest](https://www.pentrox.nl/nl/digid-pentest/) - [PCI-DSS-pentest](https://www.pentrox.nl/nl/pci-dss-pentest/) - [NEN 7510-pentest](https://www.pentrox.nl/nl/nen7510-pentest/): informatiebeveiliging in de zorg; toegang tot patiëntdossiers, NEN 7513-logging en infrastructuur getoetst aan NEN 7510. - [Geavanceerd testen](https://www.pentrox.nl/nl/geavanceerde-testen/): hub voor red teaming, scenariogebaseerde pentest, phishingsimulatie en mystery guest. - [Red teaming](https://www.pentrox.nl/nl/red-teaming/) - [Scenariogebaseerde pentest](https://www.pentrox.nl/nl/scenario-based-pentest/) - [Phishingsimulatie](https://www.pentrox.nl/nl/phishing-simulation/) - [Mystery guest](https://www.pentrox.nl/nl/mystery-guest/) - [Pentest as a Service](https://www.pentrox.nl/nl/pentest-as-a-service/) - [Pentrox Portaal](https://www.pentrox.nl/nl/portal/): bevindingen, rapporten, hertestresultaten en projectcommunicatie op één plek. - [Hoe een pentest verloopt](https://www.pentrox.nl/nl/process/) - [Voorbeeld pentestrapport](https://www.pentrox.nl/nl/voorbeeld-pentestrapport/): wat er in een rapport staat, hoe u een bevinding leest en hoe u een geanonimiseerd voorbeeld aanvraagt. - [Veelgestelde vragen](https://www.pentrox.nl/nl/faq/) - [Over Pentrox](https://www.pentrox.nl/nl/about/) - [Onze hackers](https://www.pentrox.nl/nl/hackers/): de testers achter de onderzoeken, met codenaam, rol en certificeringen; er worden geen namen of foto's gepubliceerd. - [Vertrouwen en inkoop](https://www.pentrox.nl/nl/vertrouwen/) - [Contact en offerte](https://www.pentrox.nl/nl/contact/) - [Pentest begrippen](https://www.pentrox.nl/nl/begrippen/): definities van A tot Z, onder meer [wat is een pentest](https://www.pentrox.nl/nl/wat-is-een-pentest/), [wat is een hertest](https://www.pentrox.nl/nl/wat-is-een-hertest/), [kwetsbaarheidsscan of pentest](https://www.pentrox.nl/nl/kwetsbaarheidsscan-vs-pentest/), [wat is PTaaS](https://www.pentrox.nl/nl/wat-is-ptaas/) en [black box, grey box, white box](https://www.pentrox.nl/nl/black-box-grey-box-white-box-pentest/). - [Blog (Nederlands)](https://www.pentrox.nl/nl/blog/) - [Wat kost een pentest en wat levert het u op?](https://www.pentrox.nl/nl/blog/wat-kost-een-penetratietest/): richtprijzen per onderzoek, wat de prijs bepaalt en wat er standaard in zit. - [NIS2 en pentesten: inzicht waarmee u verder kunt](https://www.pentrox.nl/nl/blog/nis2-en-penetratietesten/) - [Hoe kiest u uw ethische hackers](https://www.pentrox.nl/nl/blog/hoe-kies-je-je-ethische-hackers/) - [Uw eerste pentest: zo werkt het in vijf stappen](https://www.pentrox.nl/nl/blog/wat-te-verwachten-bij-uw-eerste-penetratietest/) - [Hoe vaak moet u een pentest laten uitvoeren?](https://www.pentrox.nl/nl/blog/hoe-vaak-pentest-laten-uitvoeren/): minstens jaarlijks en na elke grote wijziging; wat de normen vragen en een praktisch ritme. - [Een goed pentestrapport helpt uw organisatie verder](https://www.pentrox.nl/nl/blog/waarom-het-rapport-de-echte-oplevering-is/) - [Hertest na een pentest: werkt de oplossing ook echt?](https://www.pentrox.nl/nl/blog/hertest-hoe-een-fix-wordt-bewezen/) - [AI versus mens in penetratietesten: de aanpak van Pentrox](https://www.pentrox.nl/nl/blog/ai-versus-mens-in-penetratietesten/) - [Blinde SQL-injectie achter rate limiting: DNS-exfiltratie](https://www.pentrox.nl/nl/blog/blinde-sql-injectie-dns-exfiltratie/): out-of-band DNS-exfiltratie wanneer afleiden wordt afgeknepen, de cookie als sink en de maatregelen die het stoppen. - [Webapplicatie-pentest in Nederland](https://www.pentrox.nl/nl/blog/webapplicatie-pentest-nederland/): wat de test onderzoekt, de Nederlandse kaders die erom vragen (Cyberbeveiligingswet, AVG, DigiD, PCI-DSS, ISO 27001), indicatieve kosten en doorlooptijd, en wat er in het rapport moet staan. ## Contact - [Contact and quotation request](https://www.pentrox.nl/en/contact/): describe what should be tested; Pentrox agrees the scope in a short conversation and a fixed price follows. - E-mail: info@pentrox.nl - Phone: +31 6 42150488 - Address: Keizersgracht 241, 1016 EA Amsterdam, Netherlands - Chamber of Commerce (KvK): 42105876; VAT (BTW): NL869759139B01 - Client portal: https://portal.pentrox.nl - LinkedIn: https://www.linkedin.com/company/pentrox - Response within one business day. ## Optional - [Responsible disclosure](https://www.pentrox.nl/en/responsible-disclosure/): how to report a vulnerability in Pentrox systems, what to expect afterwards and within which boundaries research is permitted. - A security.txt file is published at the standard well-known path of www.pentrox.nl. - [Privacy statement](https://www.pentrox.nl/en/privacy/): which personal data Pentrox B.V. processes, for what purpose, how long it is kept and which rights apply. - [Terms and conditions](https://www.pentrox.nl/en/terms/): assignment, liability, confidentiality and governing law for penetration tests and security assessments. - [Privacyverklaring](https://www.pentrox.nl/nl/privacy/), [Algemene voorwaarden](https://www.pentrox.nl/nl/voorwaarden/), [Responsible disclosure (Nederlands)](https://www.pentrox.nl/nl/verantwoorde-openbaarmaking/) - Remaining glossary terms: [Wat is XSS](https://www.pentrox.nl/nl/wat-is-xss/), [Wat is IDOR](https://www.pentrox.nl/nl/wat-is-idor/), [Wat is CVSS](https://www.pentrox.nl/nl/wat-is-cvss/), [Wat is OSINT](https://www.pentrox.nl/nl/wat-is-osint/), [Wat is red teaming](https://www.pentrox.nl/nl/wat-is-red-teaming/), [Wat is phishing](https://www.pentrox.nl/nl/wat-is-phishing/), [Wat is social engineering](https://www.pentrox.nl/nl/wat-is-social-engineering/), [Wat is security awareness](https://www.pentrox.nl/nl/wat-is-security-awareness/), [Wat is een backdoor](https://www.pentrox.nl/nl/wat-is-een-backdoor/), [Wat is een BCP](https://www.pentrox.nl/nl/wat-is-een-bcp/), [Wat is een pentestrapport](https://www.pentrox.nl/nl/wat-is-een-pentestrapport/), [Wat is een ethical hacker](https://www.pentrox.nl/nl/wat-is-een-ethical-hacker/), [Wat is een CVE](https://www.pentrox.nl/nl/wat-is-cve/), [Wat is een zero-day](https://www.pentrox.nl/nl/wat-is-een-zero-day/), [Wat is SQL-injectie](https://www.pentrox.nl/nl/wat-is-sql-injectie/), [Wat is de OWASP Top 10](https://www.pentrox.nl/nl/wat-is-de-owasp-top-10/), [Wat is DORA](https://www.pentrox.nl/nl/wat-is-dora/), [Wat is NEN 7510](https://www.pentrox.nl/nl/wat-is-nen-7510/), [Wat is MFA](https://www.pentrox.nl/nl/wat-is-mfa/), [Wat is ransomware](https://www.pentrox.nl/nl/wat-is-ransomware/), [Wat is cloudbeveiliging](https://www.pentrox.nl/nl/wat-is-cloudbeveiliging/), [Wat is een kwetsbaarheidsscan](https://www.pentrox.nl/nl/wat-is-een-kwetsbaarheidsscan/)