Skip to content

Approach

How an
engagement runs.

Every engagement follows the same shape: remove ambiguity early, keep the work auditable in flight, and leave behind artefacts the team can use.

01

Scoping

A short call, then a written scoping document: what is in and out of scope, what success looks like, what you will receive, and what happens if something serious is found mid-engagement. Pricing is fixed before any work starts.

02

Kickoff

An hour with the stakeholders who matter to the engagement. Access, tooling, escalation paths, and rules of engagement are confirmed in writing; red team work adds a separate intent-setting session.

03

Cadence

A written status update at the end of each working week. Critical findings are surfaced the day they are found, so they can be remediated in flight rather than waiting for the final report.

04

Deliverables

A written report in plain English or Dutch. Findings are grouped by root cause and prioritised by exploitability rather than CVSS alone. Where applicable, deliverables include detection content (Sigma, KQL, or platform-native) the SOC can deploy directly.

05

Reporting

Two summaries by default: a one-page board-level narrative for non-technical stakeholders, and a technical findings report with reproducer steps for the team that will fix things. A live readout is included.

06

Post-engagement

Pentest engagements include a retest of fixed issues within 60 days. Advisory and red team engagements include a follow-up call at the three-month mark. I remain reachable by email for questions on what was delivered.

Engagement model

Engagements are scoped under NDA and billed in EUR, fixed-fee or day rate, with mutual notice of two weeks. Travel is billed at cost where applicable, with prior approval.

References available on request. Most clients are based in the Netherlands; engagements elsewhere in the EU are taken case by case.

Walk through your situation?

A 30-minute call is the easiest way to see whether this shape fits.