External security assessment · Netherlands & EU

Know what an attacker sees before they do.

An independent, non-intrusive assessment of everything your company exposes to the internet — delivered as one report your IT partner can act on and your customers will accept as evidence.

Independent Non-intrusive Written authorisation first ISO 27001 & NIS2 mapped KvK 86105434

Why companies call

Usually it starts with a question you can't answer yet

A large customer sends a supplier security questionnaire. An insurer asks what controls are in place. NIS2 turns up in a contract. The questions are specific, and the honest answer is that nobody has looked.

“Please confirm that no management interfaces are reachable from the public internet, and that multi-factor authentication is enforced on all administrative accounts.” Typical supplier questionnaire, item 14 of 60

Does NIS2 reach you?

The directive applies directly to medium and large organisations in listed sectors — and indirectly to their suppliers, because those organisations must now manage supply-chain risk. You are likely in scope if:

  • You have 50+ staff or €10M+ turnover in energy, transport, health, water, digital, food, manufacturing or public administration
  • You supply a company that does — and they've started asking questions
  • You process data or provide services on which such a company depends
  • Your customer contracts now reference “appropriate technical measures”

An assessment produces exactly the evidence those clauses ask for.

What turns up

The same weaknesses, on almost every assessment

None of these is exotic. They accumulate through growth and deferred maintenance in companies without a dedicated security function — and most can be closed with licences you already pay for.

Critical

Remote Desktop reachable directly from the internet, no VPN, no second factor

fix: ~2 hours
High

No multi-factor authentication on Microsoft 365 administrator accounts

fix: ~1 hour, €0
High

Management interfaces — firewalls, NAS, cameras, printers — exposed to the open internet

fix: ~half a day
High

VPN appliance running firmware with publicly known, actively exploited vulnerabilities

fix: 1 update window
Medium

Employee credentials present in public breach data and still valid

fix: password resets
Medium

A forgotten staging or test environment, indexed and reachable

fix: decommission
Medium

DMARC left at p=none, so anyone can send mail as your domain

fix: ~1 hour, €0
Medium

TLS configuration accepting obsolete protocols and ciphers

fix: ~1 hour

The deliverable

One report, written to be read by two people

A director needs to know how exposed the company is and what fixing it will cost. An IT partner needs enough detail to act without a follow-up call. The report is structured so neither has to read the other's half — and every finding is mapped to the ISO 27001 control and NIS2 obligation it bears on, so questionnaires can be answered straight from it.

The sample describes a fictional company. Every address in it is from the ranges reserved for documentation, and nothing in it refers to a real system.

  1. Executive summaryPlain language, one page.
  2. Risk at a glanceCounts and the findings table.
  3. Scope & authorisationWhat was examined, excluded, and permitted.
  4. FindingsEvidence, impact, recommendation, effort, owner.
  5. Three-phase planImmediate · 30 days · 90 days.
  6. Standards mappingISO 27001 controls and NIS2 obligations.
  7. Next stepsRetest and ongoing monitoring.

How it works

Four steps, about two weeks, no surprises

Day 0

Written authorisation

Scope and permission agreed and signed. Nothing is examined without it — a legal requirement, not a formality.

Days 1–5

Assessment

Your internet-facing systems examined by hand from a single known source address, so your IT partner can see exactly what we did.

Days 6–10

Report

Findings written up, rated with CVSS, mapped to standards, and delivered with a phased plan and a walkthrough call.

Week 6

Retest

Confirmation in writing that the agreed items are closed — which is the evidence your customer actually asked for.

Scope

What is examined — and what deliberately is not

Assessments are non-intrusive by design. The point is to find what is exposed, not to break it. Nothing is exploited, no data is accessed or altered, and nothing is taken offline. Publishing our limits is part of being trustworthy about the rest.

Included

  • Internet-facing systems within the agreed IP ranges
  • Domains, DNS, and email authentication (SPF, DKIM, DMARC)
  • TLS configuration and certificate hygiene
  • Microsoft 365 tenant configuration review
  • Publicly exposed credentials and forgotten environments
  • Management interfaces and remote-access services

Excluded

  • Active exploitation of any weakness found
  • Denial-of-service testing of any kind
  • Social engineering or phishing of your staff
  • Internal networks, OT and industrial systems
  • Anything outside the signed scope, ever

Questions directors ask

Before you commit

Is this legal?

Only with your written authorisation, which is why that is step one and nothing happens before it. Unauthorised scanning is a criminal offence in the Netherlands and across the EU; the signed scope is what makes the assessment lawful and is reproduced in the report.

Will it disrupt our systems?

No. The assessment observes and records; it does not exploit, flood or alter anything. Your systems will see traffic from one known address that your IT partner can recognise and, if they wish, watch.

What if you find something critical?

You hear the same day, by phone, with a concrete first step — not in the report two weeks later. Critical findings are the reason the assessment exists.

What do we need to provide?

A list of your IP ranges and domains, a signature on the authorisation, and a contact at your IT partner. Read-only access to the Microsoft 365 tenant if that is in scope. Roughly an hour of your time in total.

Who sees the report?

You decide. It is delivered to the person who signed the authorisation and nobody else. Reports are written to be shared with customers and insurers if you choose — that is largely what they are for.

Why not just run a scanner ourselves?

You should — but a scanner produces a list, not a judgement. It cannot tell you which of two hundred items matters, what it would cost you, who should fix it, or what to say to the customer who asked. That translation is the work.

Get in touch

Tell me what prompted the question

A customer questionnaire, an insurer, an audit, or simply not knowing. Describe the situation and roughly how many systems face the internet. You'll get a clear answer on scope, timing and cost before anything is committed.

Email
info@sysecured.eu
Chamber of Commerce
KvK 86105434
VAT
NL004192577B74
Coverage
Netherlands and the EU
Security
security.txt