Is a pentest a fit for your business?

Penetration Testing

Looking to run a pentest? At Tozetta we test IT, software and systems for vulnerabilities. Tozetta has extensive experience with highly trained ethical hackers. We’re well equipped to run a wide range of pentests (including to ISO27001 & DigiD standards).

With our help you’ll find out how cyber-secure your organization or business really is. Discover what a pentest can mean for your organization!

  • Interactive reporting
  • Grip on information security
  • Insight into vulnerabilities
Tozetta ethical hacker during a penetration test

[ 01 ]What is a pentest?

What is a penetration test?

What is a penetration test, and who actually runs one? On this page you'll learn everything about pentesting, from the preparation to running the pentest and delivery in Tozetta Reports.

01

What is a pentest?

A penetration test can be run on your corporate network, website and/or (mobile) application(s). The goal is to expose existing vulnerabilities and (pen)test your current digital security. During a thorough pentest an ethical hacker manually searches for flaws in your software and systems, also known as vulnerabilities. The ethical hacker then delivers the vulnerabilities found in a clear report, including a remediation plan.
02

How does running a pentest work?

With a healthy dose of creativity and a wide range of methods, ethical hackers can run a pentest. Think Black Box, Grey Box & White Box pentesting. To run a tailored pentest, a scope also needs to be defined: which applications or systems will we pentest, how long will it take, and what are your expectations of the engagement?
03

Who runs a penetration test?

A penetration test is carried out by an ethical hacker. An ethical hacker works just like a cybercriminal, except Tozetta’s hacker wants to improve your online resilience. Our hackers hold one or more certifications from OffSec, such as OSCP, OSWE or OSEP. Our ethical hackers are thoroughly screened, so you can trust that we handle confidential data correctly.

We are very satisfied with Tozetta's services and highly recommend them to companies looking for professional cybersecurity support. Their dedication, expertise, and great collaboration have had a positive impact on the security of our software.

Infowijs

Patrick van Marsbergen

Tech Lead, Infowijs

As a business service provider, Risk Solutions Caribbean conducts objective and independent investigations into wrongdoing within organizations. We also support organizations with their legally required compliance tasks. Tozetta supports us in the cybersecurity domain.

Risk Solutions Caribbean

Ruud Hamers

Managing Director, Risk Solutions Caribbean

We deliberately chose Tozetta for the combination of technical depth, pragmatic advice, and reliability. The reports are clear and immediately actionable, so findings don't sit on a shelf but actually get addressed.

ACE

ACE

Security is a key focus for us. We have an experienced development team that works on software development and security issues every day. At the same time, we wanted to deepen our knowledge further and have our approach critically reviewed by external experts. Tozetta's technical security awareness training really moved our team forward.

POM

POM

In our network, we know several parties that provide pentesting services. We had an introductory conversation with these parties, and Tozetta came out on top. Their practical approach and short lines of communication were decisive for us.

SVC Groep

SVC Groep

An annual pentest is only a snapshot in time. Now I can show at any moment whether and which vulnerabilities exist, and act on them. Every version we release is automatically tested for known vulnerabilities by the Continuous Technical Vulnerability Scanner. That gives me the feeling that we're in control, and it makes us stronger against cyber threats.

McMain Software

McMain Software

I have to say the report was really excellent. Clear, reproducible, and therefore usable. I was extremely pleasantly surprised. That’s why we highly recommend Tozetta!

SensingClues

SensingClues

As a large membership platform, we take cybersecurity extremely seriously. That's why we chose to have a pentest carried out. SeniorWeb is very happy with Tozetta's service: communication was clear and effective, and everything was ultimately documented in a professional report.

SeniorWeb

SeniorWeb

We are very satisfied with Tozetta's services and highly recommend them to companies looking for professional cybersecurity support. Their dedication, expertise, and great collaboration have had a positive impact on the security of our software.

Infowijs

Patrick van Marsbergen

Tech Lead, Infowijs

As a business service provider, Risk Solutions Caribbean conducts objective and independent investigations into wrongdoing within organizations. We also support organizations with their legally required compliance tasks. Tozetta supports us in the cybersecurity domain.

Risk Solutions Caribbean

Ruud Hamers

Managing Director, Risk Solutions Caribbean

We deliberately chose Tozetta for the combination of technical depth, pragmatic advice, and reliability. The reports are clear and immediately actionable, so findings don't sit on a shelf but actually get addressed.

ACE

ACE

Security is a key focus for us. We have an experienced development team that works on software development and security issues every day. At the same time, we wanted to deepen our knowledge further and have our approach critically reviewed by external experts. Tozetta's technical security awareness training really moved our team forward.

POM

POM

In our network, we know several parties that provide pentesting services. We had an introductory conversation with these parties, and Tozetta came out on top. Their practical approach and short lines of communication were decisive for us.

SVC Groep

SVC Groep

An annual pentest is only a snapshot in time. Now I can show at any moment whether and which vulnerabilities exist, and act on them. Every version we release is automatically tested for known vulnerabilities by the Continuous Technical Vulnerability Scanner. That gives me the feeling that we're in control, and it makes us stronger against cyber threats.

McMain Software

McMain Software

I have to say the report was really excellent. Clear, reproducible, and therefore usable. I was extremely pleasantly surprised. That’s why we highly recommend Tozetta!

SensingClues

SensingClues

As a large membership platform, we take cybersecurity extremely seriously. That's why we chose to have a pentest carried out. SeniorWeb is very happy with Tozetta's service: communication was clear and effective, and everything was ultimately documented in a professional report.

SeniorWeb

SeniorWeb

[ 02 ]Why pentest

Why penetration testing?

Running a penetration test can mean a great deal for an organization or business. The numbers below don't lie: cybercrime keeps getting more common. Running a pentest exposes vulnerabilities in your systems, network or applications before hackers do.

  • It tests and assesses the cybersecurity of your systems and applications
  • It exposes vulnerabilities so you can remediate them
  • Under GDPR you’re required to protect personal data against leaks and misuse
  • A pentest proactively reduces the chance of a hack and protects business continuity
  • A real ethical hacker looks at your systems manually, with a creative eye
Running a pentest at Tozetta Ethical Hacking
71%

of ransomware victims are SMEs.

270K

is the average damage caused by a hack.

50+

vulnerabilities are reported every day.

[ 03 ]Our services

What can you have pentested?

Hover a service for a short description, or click through for all the details.

Ian van der Wurff, ethical hacker

I've capped off 5+ years of experience as an ethical hacker with an OSCP, OSED, OSWE, OSEP & OSCE3 certification. With that knowledge, I make sure your networks, websites, and mobile applications are tested thoroughly.

Ian van der Wurff

Ethical Hacking Lead, Tozetta

OSCP
OSED
OSWE
OSEP
OSCE3

[ 04 ]Pentest methods

Penetration test methods

Black, Grey or White box? Pick a method below and see instantly how much knowledge the ethical hacker gets up front, and therefore how realistic the attack is.

The hacker starts completely blind

Black box Pentest

In a black box penetration testthe organization gives the ethical hacker no information about the systems and IT structure up front. The ethical hacker only receives a scope consisting of a URL and/or IP addresses. This mimics how a "real hacker" operates: a malicious actor obviously has no internal knowledge either and has to gather everything themselves. This gives you the most realistic picture of what an attacker without prior knowledge can actually achieve.

Knowledge level up front0%

What the hacker sees up front

URL, IP addresses or external application(s)
Credentials or limited (user) access
Source code, architecture and/or admin rights

[ 05 ]Investment

What does a pentest cost?

At Tozetta we want to be very transparent about pentest costs. The price always depends on the size and complexity of an application and/or internal network. The pentest prices below are indications.

Not sure? Feel free to get in touch to determine the pentest price for your organization.

What are the pentest costs?

Pentest pricing

At Tozetta we bring the highest quality to every pentest. Every project comes with the following added value:

  • We always test with multiple specialist hackers
  • Tozetta’s hackers are trained to Offensive Security standards
  • Tozetta goes deeper than most standards and guidelines such as OWASP or PTES
  • We always debrief the pentest free of charge and perform a free retest
  • You get access to Tozetta Reports, our own pentest reporting tool!

Lite

Penetration test

3495

  • Informational website
  • Static web application
  • Max. 4 IP addresses
  • Max. 1 domain
Get in touch

Business

Penetration test

4495

  • Pentest behind a login
  • Focus on front & back end
  • Max. 8 IP addresses
  • Max. 1 domain
Get in touch
Most popular

Pro

Penetration test

5495

  • Everything in Business
  • API pentesting
  • Testing across roles
  • Max. 16 IP addresses
  • Max. 3 domains
Get in touch

Expert

Penetration test

6995

  • Everything in Business & Pro
  • Complex IT landscape
  • Complex web application(s)
  • Max. 32 IP addresses
  • Max. 5 domains
Get in touch
Kevin van den Eshof

Almost every company has a website. Many companies don't realize that they themselves are responsible for the cybersecurity of their site. If a data breach occurs, you as the website owner are liable for it, not your website builder...

Kevin van den Eshof

Co-founder & Private Investigator, Tozetta

[ 06 ]Tozetta Reports

Tozetta Reports

Tozetta Reports makes the results of every pentest instantly clear and actionable, without long, hard-to-navigate PDF reports. Our interactive tool gives you real-time insight into vulnerabilities, lets you easily track progress and generate tailored reports. Optionally we offer an integrated vulnerability scanner for continuous monitoring of your security, or connect insights from our AI-scanning to the same dashboard. This way Tozetta Reports helps you respond to risks faster and more efficiently, so you stay in control of your information security. Curious what the team behind Tozetta can do for you? Get in touch.

Allow marketing cookies to watch this YouTube video.

[ 07 ]Why Tozetta

Why run a pentest with Tozetta?

At Tozetta we have one goal: exposing vulnerabilities in software and systems. By running a pentest we hope to provide insight and create awareness. Beyond exposing vulnerabilities, we care deeply that the vulnerabilities identified actually get fixed.

Throughout the pentest you have 1-on-1 contact with the ethical hacking lead. This gives room to ask questions and gain a better understanding of a hacker’s "mindset". This way we don’t just fix existing vulnerabilities. We also try to contribute to the cybersecurity knowledge level within your organization.

10+ years of experience Certified hackersIndependent & objective
Get in touch
Kevin van den Eshof, co-founder Tozetta

Certifications

Our ethical hackers are broadly certified

From OffSec to Hack The Box: the Tozetta team sets the bar high with internationally recognized, hands-on certifications. We put that in-depth expertise to work in every pentest, so organizations can count on thorough, high-quality security research.

OSCP

OSCP

Offensive Security Certified Professional

OSWE

OSWE

Offensive Security Web Expert

OSEP

OSEP

Offensive Security Experienced Penetration Tester

OSED

OSED

Offensive Security Exploit Developer

OSCE3

OSCE3

Offensive Security Certified Expert 3

CPTS

CPTS

HTB Certified Penetration Testing Specialist

CWEE

CWEE

HTB Certified Web Exploitation Expert

CWES

CWES

HTB Certified Web Exploitation Specialist

AED

AED

Android Exploit Developer

APIsec

APIsec

API Penetration Testing

eWPT

eWPT

Web Application Penetration Tester

BED

BED

Browser Exploit Design

Corelan

Corelan

Windows Expert-Level Stack Exploit Dev

OSCP

OSCP

Offensive Security Certified Professional

OSWE

OSWE

Offensive Security Web Expert

OSEP

OSEP

Offensive Security Experienced Penetration Tester

OSED

OSED

Offensive Security Exploit Developer

OSCE3

OSCE3

Offensive Security Certified Expert 3

CPTS

CPTS

HTB Certified Penetration Testing Specialist

CWEE

CWEE

HTB Certified Web Exploitation Expert

CWES

CWES

HTB Certified Web Exploitation Specialist

AED

AED

Android Exploit Developer

APIsec

APIsec

API Penetration Testing

eWPT

eWPT

Web Application Penetration Tester

BED

BED

Browser Exploit Design

Corelan

Corelan

Windows Expert-Level Stack Exploit Dev

[ 08 ]Independence

The importance of independent pentesting

Independent pentests bring a new level of objectivity and expertise. Tozetta's external ethical hackers aren't biased by knowledge of the internal IT structure, so they uncover vulnerabilities that get overlooked internally.

[ Reason 1 ]

Existing IT partner / MSP

An existing IT partner, MSP or cybersecurity specialist can also run a pentest. But is that ever fully objective? If that same party rolled out the entire IT or cybersecurity setup, should they also be the one testing whether it’s secure?

Risk: conflicts of interest & blind spots

[ Reason 2 ]

Independent ethical hacker

Tozetta’s external ethical hackers aren’t biased by knowledge of the internal IT structure. This independent approach guarantees a thorough assessment of your software and systems’ security.

Result: objective, thorough & unbiased

[ 09 ]Get started

Request a no-obligation consultation!

At Tozetta you can request a no-obligation consultation. We’ll think along with your cybersecurity question free of charge and can put together a concrete proposal for a possible partnership. Curious about the possibilities of a pentest with Tozetta? Get in touch using the form below.

  • Free advice
  • No obligation
  • Fresh insights
  • Reply within 1 business day
Read our privacy statement here

Partners

In cybersecurity, you work together:

AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer

Frequently asked pentest questions

How long does a pentest take?
This varies enormously per pentest. An engagement can range from a few days to several weeks, depending on the scope, such as the diversity of assets (internal environment, web application(s), mobile applications and/or cloud environments), and the testing approach: whitebox, greybox or blackbox pentesting. If you contact us and fill in our questionnaire, you’ll have a quote including an estimated time investment within a few days.
Which pentest method fits my organization?
As covered above, Whitebox, Greybox and Blackbox are the options. It varies per environment, but the advice is often a whitebox or greybox pentest. Why? An ethical hacker with prior knowledge can validate issues and make relevant assessments much faster, so time is often spent more usefully than during a blackbox pentest. A blackbox pentest can, however, give good insight into whether a "real" (ethical) hacker can break into your systems. Grey- and whitebox pentests assume a breach has already happened, i.e. that someone is already inside and has gained access to critical systems.
How do I prioritize the vulnerabilities found?
You don’t, we do that for you! We score every vulnerability found as critical, high, medium, low or informational risk. In the pentest report we advise what should be fixed first, helping with prioritization. Our reports are clear and try to illustrate the possible business impact if things go wrong. That’s often hard to express in cost, but we can explain the risk behind the vulnerability. That makes our pentest reports relevant for colleagues without an IT/security background too.
How do I convince my colleagues to run a pentest?
This question comes up a lot. Many IT professionals know how important a pentest can be for the organization, yet many companies haven’t freed up budget for it, or find it hard to convince "non-technical" colleagues. At Tozetta we offer OSINT and cybersecurity awareness trainings, among others, where we help convey the importance of cybersecurity and the financial consequences of cybercrime. If you as an IT professional find this hard to convey, we’re happy to talk to the colleagues involved directly. Think of it as a free cybersecurity awareness training!
How much does a pentest cost?
Hiring an ethical hacker to run a pentest typically costs between €125 and €200 per hour. The ethical hacker actively searches for vulnerabilities, supported by vulnerability scanning tools. The value of the ethical hacker lies in human logic and the ability to combine various vulnerabilities to actually verify risk. It’s hard to estimate what a pentest costs in general, it often starts at two days. At Tozetta we’re always happy to have the conversation. Based on your needs we put together a no-obligation quote, so you know exactly what the price is for your situation.