We look at your environment the way an attacker does.
A security assessment shows where you are vulnerable: technically and organisationally. With the ten questions an insurer, auditor or major customer wants answered, and a plan to be able to answer them. If you only want to know whether the door is really shut, a pentest is also available on its own.

Sound familiar?
There has been an incident, at your company or at a peer. The cyber insurer sets requirements. A major customer sends a questionnaire. NIS2 affects your supply chain. Or it simply keeps you up at night.
Situations in which clients end up with us
- "We had a pentest last year", but nobody knows who fixed the findings.
- The insurer asks about MFA, backup and logging and you are not sure of the answer.
- A customer demands an ISO or NIS2 statement.
- Your IT person does their best, but security is a different profession.
Four steps, no surprises.
Define scope
What is critical for your business? Which systems, which data, which people? We start with what you cannot do without.
Technical review
External and internal attack surface, Microsoft 365 and Azure configuration, identity and permissions, endpoints and backup. A targeted pentest where needed.
Organisational review
Policy, responsibilities, incident procedure, suppliers and awareness. The ten questions of your insurer or auditor.
Report and plan
Findings sorted by risk, each with: what, why, how and in which order. And an offer to close them together, because a report secures nothing.
What's included
- External attack surface (what a hacker sees from outside)
- Microsoft 365 / Entra ID / Azure configuration
- Permissions and identity: who can do what, and why
- Endpoint and backup check
- Organisational review incl. NIS2 questions
- Prioritised report with approach
- Retest after remediation
"A report secures nothing. We find the gaps, close them and keep them closed."Martijn Mol, Remarx
Frequently asked questions
What is the difference between a security assessment and a pentest?
An assessment looks broadly: technology and organisation, from permissions and identity to backup and policy. A pentest is narrower and answers one question: can an attacker get in within the agreed scope? You can take either separately or both.
What does a security assessment cost?
That depends on size and scope, so we quote after a short intake. A standalone pentest does have a fixed price. We would rather quote honestly than publish a from-price that turns out not to hold.
Do we get a retest after fixing things?
Yes. Once you have addressed the findings, we test again to confirm the gaps are genuinely closed. That retest is included in both the assessment and the pentest.
Is this enough for our insurer or for NIS2?
The assessment answers the questions insurers, auditors and large customers ask, and delivers a prioritised plan. Whether it makes you fully NIS2-compliant depends on your sector and size; we cover that in the advisory session.
Your next step.
Managed Detection & Response
Monitoring that actually intervenes. Attackers work outside office hours, and technology is better at that than people are.
Read moreCISO as a Service
Security leadership at board level. A full-time CISO easily costs € 10,000 to € 15,000 a month, if you can find one.
Read moreMicrosoft 365 Health Check
Where is money leaking and where is the risk?. Hardly anyone knows what their Microsoft environment costs per month and how much of it is actually used.
Read moreTwenty minutes with Martijn or Remy.
No account manager, no call centre. You speak directly with one of the founders. You tell us what's going on; we tell you honestly whether and how we can help. Even if the answer is 'you don't need us'.


Pick a time
On working days, via Teams or phone. Choose a slot in our calendar and get an instant confirmation.
Open the calendar Prefer to call? 085 060 9448 · Or send a message