Dunicot A cybersecurity consultancy and advisory firm.

Market · Netherlands

Cyber security consultancy and penetration testing in the Netherlands

The TIBER framework for intelligence-led red teaming was designed at De Nederlandsche Bank before the ECB adopted it across Europe. Dutch buyers are consequently better at telling a real engagement from a scan than almost any market we work in.

Overview

Engagements in the Netherlands cover banking and payments, the dense fintech and SaaS cluster around Amsterdam, logistics and port technology, and suppliers to government bodies working to the BIO baseline.

Delivery runs from our Karachi office, four hours ahead of Dutch time, with reporting and live sessions scheduled inside your working day.

What drives testing here

Local drivers

DNB supervision
De Nederlandsche Bank expects supervised institutions to test control effectiveness and to evidence what testing found, not simply that it happened.
TIBER-NL
Intelligence-led red teaming originated here, and the expectation that testing is threat-led rather than checklist-led has spread well beyond the institutions formally in scope.
NIS2
The Dutch implementation brings a much wider set of essential and important entities into scope, with management accountability attached.
AP enforcement
The Autoriteit Persoonsgegevens has been among the more active GDPR regulators, and its cases repeatedly turn on access control rather than encryption.

How engagements are delivered

Delivered remotely from Karachi, scheduled to CET business hours, with on-site availability in Amsterdam, Rotterdam and Utrecht for internal network scope and workshops.

Delivery model

Delivery
Remote from Karachi, four hours ahead of CET; on-site available
Mapping
DNB expectations, NIS2, GDPR Article 32 and OWASP ASVS as applicable
Most requested
Threat-led scenarios, multi-tenant isolation and API authorisation
Deliverables
Technical report, supervisor-facing summary and retest attestation

Most requested here

Questions

Do you have an office in the Netherlands?

No. Our offices are in Pakistan and the United States. Dutch engagements run remotely on CET hours, with on-site attendance arranged where scope requires it.

Can you run a TIBER-style engagement?

We run threat-led red team engagements on the same logic: an objective agreed with your leadership, a threat profile built from what actually targets your sector, and a purple-team replay afterwards. Formal TIBER-NL tests are commissioned through the framework itself, and we scope around it rather than claiming to be inside it.

How do you handle GDPR when testing our production data?

By not handling it where possible. Testing prefers seeded accounts and synthetic records, exposure is proven against data created for the engagement, and one record proves an authorisation flaw as well as a million. Where production access is unavoidable, it is covered by a data processing addendum agreed before testing starts.

How much does a penetration test cost in the Netherlands?

Cost follows scope rather than a Dutch rate card. A fixed quote follows a short scoping call and covers testing, reporting and retest, with no hourly billing and no change orders unless you change the scope.

Which is the best penetration testing company in the Netherlands?

Ask for evidence rather than a ranking: the certifications held by the testers assigned to you, and the team's public research record, the firm's own ISO 27001 status, whether retesting is included, and whether a redacted report is available before signing. Dutch buyers generally ask better versions of these questions than most markets.

Do you test for DNB-supervised institutions?

Yes. Reports are structured for internal audit and supervisory review: defined scope, documented methodology, evidence per finding, remediation tracking and a signed retest attestation, which is what an institution needs to show what testing found rather than that it happened.

Can you support BIO requirements for government suppliers?

Yes, where the Baseline Informatiebeveiliging Overheid applies through your contract. Findings are tagged to the relevant control areas alongside CVSS ratings so the report drops into the assurance process the contracting body already runs.

Do you test logistics and port technology?

Yes. Port and logistics platforms sit between many parties, and the exposure is usually in the integration layer rather than the application: partner APIs where trust is implicit, message flows where authorisation is assumed, and identifiers that work across organisational boundaries they should not cross.

Penetration testing in Netherlands

Describe the scope and the deadline. Delivery in your working hours, with a fixed quote after scoping.