Penetration Testing
Looking to run a pentest? At Tozetta we test IT, software and systems for vulnerabilities. Tozetta has extensive experience with highly trained ethical hackers. We’re well equipped to run a wide range of pentests (including to ISO27001 & DigiD standards).
With our help you’ll find out how cyber-secure your organization or business really is. Discover what a pentest can mean for your organization!
- Interactive reporting
- Grip on information security
- Insight into vulnerabilities

[ 01 ]What is a pentest?
What is a penetration test?
What is a penetration test, and who actually runs one? On this page you'll learn everything about pentesting, from the preparation to running the pentest and delivery in Tozetta Reports.
What is a pentest?
How does running a pentest work?
Who runs a penetration test?
“We are very satisfied with Tozetta's services and highly recommend them to companies looking for professional cybersecurity support. Their dedication, expertise, and great collaboration have had a positive impact on the security of our software.”
“As a business service provider, Risk Solutions Caribbean conducts objective and independent investigations into wrongdoing within organizations. We also support organizations with their legally required compliance tasks. Tozetta supports us in the cybersecurity domain.”
“We deliberately chose Tozetta for the combination of technical depth, pragmatic advice, and reliability. The reports are clear and immediately actionable, so findings don't sit on a shelf but actually get addressed.”
“Security is a key focus for us. We have an experienced development team that works on software development and security issues every day. At the same time, we wanted to deepen our knowledge further and have our approach critically reviewed by external experts. Tozetta's technical security awareness training really moved our team forward.”
“In our network, we know several parties that provide pentesting services. We had an introductory conversation with these parties, and Tozetta came out on top. Their practical approach and short lines of communication were decisive for us.”
“An annual pentest is only a snapshot in time. Now I can show at any moment whether and which vulnerabilities exist, and act on them. Every version we release is automatically tested for known vulnerabilities by the Continuous Technical Vulnerability Scanner. That gives me the feeling that we're in control, and it makes us stronger against cyber threats.”
“I have to say the report was really excellent. Clear, reproducible, and therefore usable. I was extremely pleasantly surprised. That’s why we highly recommend Tozetta!”
“As a large membership platform, we take cybersecurity extremely seriously. That's why we chose to have a pentest carried out. SeniorWeb is very happy with Tozetta's service: communication was clear and effective, and everything was ultimately documented in a professional report.”
“We are very satisfied with Tozetta's services and highly recommend them to companies looking for professional cybersecurity support. Their dedication, expertise, and great collaboration have had a positive impact on the security of our software.”
“As a business service provider, Risk Solutions Caribbean conducts objective and independent investigations into wrongdoing within organizations. We also support organizations with their legally required compliance tasks. Tozetta supports us in the cybersecurity domain.”
“We deliberately chose Tozetta for the combination of technical depth, pragmatic advice, and reliability. The reports are clear and immediately actionable, so findings don't sit on a shelf but actually get addressed.”
“Security is a key focus for us. We have an experienced development team that works on software development and security issues every day. At the same time, we wanted to deepen our knowledge further and have our approach critically reviewed by external experts. Tozetta's technical security awareness training really moved our team forward.”
“In our network, we know several parties that provide pentesting services. We had an introductory conversation with these parties, and Tozetta came out on top. Their practical approach and short lines of communication were decisive for us.”
“An annual pentest is only a snapshot in time. Now I can show at any moment whether and which vulnerabilities exist, and act on them. Every version we release is automatically tested for known vulnerabilities by the Continuous Technical Vulnerability Scanner. That gives me the feeling that we're in control, and it makes us stronger against cyber threats.”
“I have to say the report was really excellent. Clear, reproducible, and therefore usable. I was extremely pleasantly surprised. That’s why we highly recommend Tozetta!”
“As a large membership platform, we take cybersecurity extremely seriously. That's why we chose to have a pentest carried out. SeniorWeb is very happy with Tozetta's service: communication was clear and effective, and everything was ultimately documented in a professional report.”
[ 02 ]Why pentest
Why penetration testing?
Running a penetration test can mean a great deal for an organization or business. The numbers below don't lie: cybercrime keeps getting more common. Running a pentest exposes vulnerabilities in your systems, network or applications before hackers do.
- It tests and assesses the cybersecurity of your systems and applications
- It exposes vulnerabilities so you can remediate them
- Under GDPR you’re required to protect personal data against leaks and misuse
- A pentest proactively reduces the chance of a hack and protects business continuity
- A real ethical hacker looks at your systems manually, with a creative eye

of ransomware victims are SMEs.
is the average damage caused by a hack.
vulnerabilities are reported every day.
[ 03 ]Our services
What can you have pentested?
Hover a service for a short description, or click through for all the details.

“I've capped off 5+ years of experience as an ethical hacker with an OSCP, OSED, OSWE, OSEP & OSCE3 certification. With that knowledge, I make sure your networks, websites, and mobile applications are tested thoroughly.”





[ 04 ]Pentest methods
Penetration test methods
Black, Grey or White box? Pick a method below and see instantly how much knowledge the ethical hacker gets up front, and therefore how realistic the attack is.
The hacker starts completely blind
Black box Pentest
In a black box penetration testthe organization gives the ethical hacker no information about the systems and IT structure up front. The ethical hacker only receives a scope consisting of a URL and/or IP addresses. This mimics how a "real hacker" operates: a malicious actor obviously has no internal knowledge either and has to gather everything themselves. This gives you the most realistic picture of what an attacker without prior knowledge can actually achieve.
What the hacker sees up front
[ 05 ]Investment
What does a pentest cost?
At Tozetta we want to be very transparent about pentest costs. The price always depends on the size and complexity of an application and/or internal network. The pentest prices below are indications.
Not sure? Feel free to get in touch to determine the pentest price for your organization.

Pentest pricing
At Tozetta we bring the highest quality to every pentest. Every project comes with the following added value:
- We always test with multiple specialist hackers
- Tozetta’s hackers are trained to Offensive Security standards
- Tozetta goes deeper than most standards and guidelines such as OWASP or PTES
- We always debrief the pentest free of charge and perform a free retest
- You get access to Tozetta Reports, our own pentest reporting tool!
Lite
Penetration test
€3495
- Informational website
- Static web application
- Max. 4 IP addresses
- Max. 1 domain
Business
Penetration test
€4495
- Pentest behind a login
- Focus on front & back end
- Max. 8 IP addresses
- Max. 1 domain
Pro
Penetration test
€5495
- Everything in Business
- API pentesting
- Testing across roles
- Max. 16 IP addresses
- Max. 3 domains
Expert
Penetration test
€6995
- Everything in Business & Pro
- Complex IT landscape
- Complex web application(s)
- Max. 32 IP addresses
- Max. 5 domains

“Almost every company has a website. Many companies don't realize that they themselves are responsible for the cybersecurity of their site. If a data breach occurs, you as the website owner are liable for it, not your website builder...”
[ 06 ]Tozetta Reports
Tozetta Reports
Tozetta Reports makes the results of every pentest instantly clear and actionable, without long, hard-to-navigate PDF reports. Our interactive tool gives you real-time insight into vulnerabilities, lets you easily track progress and generate tailored reports. Optionally we offer an integrated vulnerability scanner for continuous monitoring of your security, or connect insights from our AI-scanning to the same dashboard. This way Tozetta Reports helps you respond to risks faster and more efficiently, so you stay in control of your information security. Curious what the team behind Tozetta can do for you? Get in touch.
Allow marketing cookies to watch this YouTube video.
[ 07 ]Why Tozetta
Why run a pentest with Tozetta?
At Tozetta we have one goal: exposing vulnerabilities in software and systems. By running a pentest we hope to provide insight and create awareness. Beyond exposing vulnerabilities, we care deeply that the vulnerabilities identified actually get fixed.
Throughout the pentest you have 1-on-1 contact with the ethical hacking lead. This gives room to ask questions and gain a better understanding of a hacker’s "mindset". This way we don’t just fix existing vulnerabilities. We also try to contribute to the cybersecurity knowledge level within your organization.

Certifications
Our ethical hackers are broadly certified
From OffSec to Hack The Box: the Tozetta team sets the bar high with internationally recognized, hands-on certifications. We put that in-depth expertise to work in every pentest, so organizations can count on thorough, high-quality security research.

OSCP
Offensive Security Certified Professional

OSWE
Offensive Security Web Expert

OSEP
Offensive Security Experienced Penetration Tester

OSED
Offensive Security Exploit Developer

OSCE3
Offensive Security Certified Expert 3

CPTS
HTB Certified Penetration Testing Specialist

CWEE
HTB Certified Web Exploitation Expert

CWES
HTB Certified Web Exploitation Specialist

AED
Android Exploit Developer

APIsec
API Penetration Testing

eWPT
Web Application Penetration Tester

BED
Browser Exploit Design

Corelan
Windows Expert-Level Stack Exploit Dev

OSCP
Offensive Security Certified Professional

OSWE
Offensive Security Web Expert

OSEP
Offensive Security Experienced Penetration Tester

OSED
Offensive Security Exploit Developer

OSCE3
Offensive Security Certified Expert 3

CPTS
HTB Certified Penetration Testing Specialist

CWEE
HTB Certified Web Exploitation Expert

CWES
HTB Certified Web Exploitation Specialist

AED
Android Exploit Developer

APIsec
API Penetration Testing

eWPT
Web Application Penetration Tester

BED
Browser Exploit Design

Corelan
Windows Expert-Level Stack Exploit Dev
[ 08 ]Independence
The importance of independent pentesting
Independent pentests bring a new level of objectivity and expertise. Tozetta's external ethical hackers aren't biased by knowledge of the internal IT structure, so they uncover vulnerabilities that get overlooked internally.
Existing IT partner / MSP
An existing IT partner, MSP or cybersecurity specialist can also run a pentest. But is that ever fully objective? If that same party rolled out the entire IT or cybersecurity setup, should they also be the one testing whether it’s secure?
Risk: conflicts of interest & blind spots
Independent ethical hacker
Tozetta’s external ethical hackers aren’t biased by knowledge of the internal IT structure. This independent approach guarantees a thorough assessment of your software and systems’ security.
Result: objective, thorough & unbiased
[ 09 ]Get started
Request a no-obligation consultation!
At Tozetta you can request a no-obligation consultation. We’ll think along with your cybersecurity question free of charge and can put together a concrete proposal for a possible partnership. Curious about the possibilities of a pentest with Tozetta? Get in touch using the form below.
- Free advice
- No obligation
- Fresh insights
- Reply within 1 business day
Partners
In cybersecurity, you work together:































































































































