Customer Case Tozetta x SVC Groep: More Confidence in Digital Resilience
SVC Groep shares how a pentest by Tozetta provided insight, clear priorities, and more confidence in their cyber security.
SVC Groep approached Tozetta to carry out a penetration test. After a brief but careful selection process, it quickly became clear that Tozetta was the right partner. In this customer case, we take a closer look at the added value of a pentest and the reasons why SVC Groep chose Tozetta as their pentesting partner. Through a conversation with Richard Meinders, we gain insight into how SVC Groep experienced the collaboration and what impact it had on their security approach.
What was the most important reason for you to have a pentest carried out?
Richard: "As an auditing organization, we hold our clients to a certain standard when it comes to their business operations, including in the areas of privacy and information security. That's why we believe we need to be best-in-class in this area ourselves. A few years ago, we already had a general security check carried out. Although it didn't reveal any security risks, the ISO 27001 process we're currently starting up is a good reason to have our application thoroughly tested."
Why did you choose to work with Tozetta?
Richard: "In our network, we know several parties that offer similar services. We had an introductory conversation with these parties, and Tozetta came out on top. The practical approach and short lines of communication were what tipped the scales for us."
Which insights have been the most valuable to you?
Richard: "Our developers specialize in building software and consistently keep security high on the agenda. However, an ethical hacker approaches software from a different perspective, with a different goal and different experience. During this pentest, it became clear that ethical hackers think fundamentally differently than developers, which led to new insights and a sharper picture of our security."
How does Tozetta Reports translate technical findings into concrete action points?
Richard: "For me, the concrete vulnerabilities are gibberish — fortunately I understand the executive summary and the possible business impact. Luckily, our developer fully understands the report. To each their own, I suppose. In your environment, the findings are presented clearly for them, with the right priority. It's also handy that it includes good instructions for resolving the identified findings."
Did you learn anything else from working with Tozetta?
Richard: "The collaboration went very smoothly. The contact between the ethical hackers and our developer was also very useful and valuable. What we learned is that, to really get a good picture of the risks, you need to be able to think completely 'outside the box.' Tozetta can genuinely help by carrying out a controlled pentest."
What would you tell other organizations about the importance of insight and demonstrability after a pentest?
Richard: "No matter how well you do your job, you always view it through your own vision and framework regarding data security. Having a pentest carried out also means your organization is critically examined by a third party. It teaches you that they always look at things differently and are organization-independent. That means you shift from 'thinking' that things are fine to 'knowing' that things are fine. That's a reassuring feeling and contributes to the quality of the service you want to deliver."