External security assessment · Netherlands & EU
An independent, non-intrusive assessment of everything your company exposes to the internet — delivered as one report your IT partner can act on and your customers will accept as evidence.
Why companies call
A large customer sends a supplier security questionnaire. An insurer asks what controls are in place. NIS2 turns up in a contract. The questions are specific, and the honest answer is that nobody has looked.
The directive applies directly to medium and large organisations in listed sectors — and indirectly to their suppliers, because those organisations must now manage supply-chain risk. You are likely in scope if:
An assessment produces exactly the evidence those clauses ask for.
What turns up
None of these is exotic. They accumulate through growth and deferred maintenance in companies without a dedicated security function — and most can be closed with licences you already pay for.
Remote Desktop reachable directly from the internet, no VPN, no second factor
fix: ~2 hoursNo multi-factor authentication on Microsoft 365 administrator accounts
fix: ~1 hour, €0Management interfaces — firewalls, NAS, cameras, printers — exposed to the open internet
fix: ~half a dayVPN appliance running firmware with publicly known, actively exploited vulnerabilities
fix: 1 update windowEmployee credentials present in public breach data and still valid
fix: password resetsA forgotten staging or test environment, indexed and reachable
fix: decommissionDMARC left at p=none, so anyone can send mail as your domain
TLS configuration accepting obsolete protocols and ciphers
fix: ~1 hourThe deliverable
A director needs to know how exposed the company is and what fixing it will cost. An IT partner needs enough detail to act without a follow-up call. The report is structured so neither has to read the other's half — and every finding is mapped to the ISO 27001 control and NIS2 obligation it bears on, so questionnaires can be answered straight from it.




The sample describes a fictional company. Every address in it is from the ranges reserved for documentation, and nothing in it refers to a real system.
How it works
Scope and permission agreed and signed. Nothing is examined without it — a legal requirement, not a formality.
Your internet-facing systems examined by hand from a single known source address, so your IT partner can see exactly what we did.
Findings written up, rated with CVSS, mapped to standards, and delivered with a phased plan and a walkthrough call.
Confirmation in writing that the agreed items are closed — which is the evidence your customer actually asked for.
Scope
Assessments are non-intrusive by design. The point is to find what is exposed, not to break it. Nothing is exploited, no data is accessed or altered, and nothing is taken offline. Publishing our limits is part of being trustworthy about the rest.
Questions directors ask
Only with your written authorisation, which is why that is step one and nothing happens before it. Unauthorised scanning is a criminal offence in the Netherlands and across the EU; the signed scope is what makes the assessment lawful and is reproduced in the report.
No. The assessment observes and records; it does not exploit, flood or alter anything. Your systems will see traffic from one known address that your IT partner can recognise and, if they wish, watch.
You hear the same day, by phone, with a concrete first step — not in the report two weeks later. Critical findings are the reason the assessment exists.
A list of your IP ranges and domains, a signature on the authorisation, and a contact at your IT partner. Read-only access to the Microsoft 365 tenant if that is in scope. Roughly an hour of your time in total.
You decide. It is delivered to the person who signed the authorisation and nobody else. Reports are written to be shared with customers and insurers if you choose — that is largely what they are for.
You should — but a scanner produces a list, not a judgement. It cannot tell you which of two hundred items matters, what it would cost you, who should fix it, or what to say to the customer who asked. That translation is the work.
Get in touch
A customer questionnaire, an insurer, an audit, or simply not knowing. Describe the situation and roughly how many systems face the internet. You'll get a clear answer on scope, timing and cost before anything is committed.