Services

Security Services —
Delivered Remotely

Every engagement is executed 100% remote. No travel costs, no delays — you get senior CISSP + OSCP+ certified expertise wherever you are in the EU.

Core Services

The services I deliver most

All core services include an executive summary, full technical report with PoC evidence, and a debrief call.

From €3,500

Web Application Penetration Test

In-depth security assessment of web applications following OWASP WSTG and ASVS methodology. Covers authentication, authorisation, injection flaws, business logic, and configuration weaknesses — not just automated scanning.

Timeline 3–5 business days
You provide URL + test accounts
Deliverable Executive + technical report + debrief
From €2,500

API Security Assessment

Security testing of REST, GraphQL, and WebSocket APIs. Focuses on auth and authorisation flaws, input validation, rate limiting, data exposure, and business logic errors — issues automated tools consistently miss.

Timeline 2–4 business days
You provide API endpoints + credentials / tokens
Deliverable Findings + PoC + remediation per vulnerability
From €3,500

Cloud Security Review

Configuration and security assessment of AWS, Azure, and GCP environments. Covers IAM policies, network configuration, storage permissions, logging and monitoring gaps, and compliance control mapping.

Timeline 2–3 business days
You provide Read-only IAM role or Reader access
Deliverable Risk-prioritised findings + remediation roadmap
From €2,000

External Network Penetration Test

Assessment of your internet-facing infrastructure: port scanning, service enumeration, vulnerability identification, and controlled exploitation. Covers the attack surface your organisation exposes to the public internet.

Timeline 2–3 business days
You provide IP ranges in scope + written authorisation
Deliverable Technical report with severity ratings

Additional Services

More ways I can help

Specialist services to complement your security programme or address specific needs.

Internal Network Pentest

From €3,500

Assessment of your internal network via VPN. Active Directory enumeration, lateral movement paths, and privilege escalation. Requires a stable VPN setup.

Secure Code Review / SAST

From €3,000

Manual and automated analysis of source code. Identifies vulnerabilities introduced during development — before they reach production.

OSINT / Attack Surface Mapping

From €1,500

External reconnaissance: exposed assets, leaked credentials, shadow IT, and publicly accessible sensitive data. Understand what attackers see before they do.

NIS2 / DORA Gap Analysis

From €3,500

Compliance readiness assessment with control mapping against NIS2 or DORA requirements. Delivers a gap analysis, remediation roadmap, and regulator-ready report.

vCISO / Security Advisory

€125–150/hr

Part-time security leadership on a retainer or project basis. Strategy, risk management, board reporting, and programme oversight — without the cost of a full-time hire.

Red Team Assessment

On request

Realistic adversary simulation targeting people, processes, and technology. Includes phishing, chained exploitation, and persistence — scoped and priced per engagement.

Not currently offered

  • Physical penetration testing / on-site red team
  • On-site internal pentest without VPN access
  • In-person social engineering
  • Live on-site security awareness training

Remote Delivery

How a remote engagement works

Every step is designed to be frictionless — for you and your team.

1

Scoping call

30 minutes to align on target, timeline, and objectives.

2

Authorisation

Scope of work and NDA signed. Testing doesn't start without written sign-off.

3

Testing

I execute the engagement remotely. You get a brief daily update if the timeline is more than 2 days.

4

Draft review

You review the draft report and flag any questions before the final version.

5

Debrief

A call to walk through findings, answer questions, and discuss remediation priority.

Quick Reference

What you provide per service

A simple overview so you know what to prepare before we start.

Service You provide Timeline Starting price Type
Web Application Pentest URL + test accounts 3–5 days €3,500 Core
API Security Assessment Endpoints + credentials 2–4 days €2,500 Core
Cloud Security Review Read-only access 2–3 days €3,500 Core
External Network Pentest IP ranges + authorisation 2–3 days €2,000 Core
Internal Network Pentest VPN access + domain account 4–5 days €3,500 Add-on
Secure Code Review Repository access 3–5 days €3,000 Add-on
OSINT / Attack Surface Company name + domain 1–2 days €1,500 Add-on
NIS2 / DORA Gap Analysis Documentation + stakeholder 3–5 days €3,500 Add-on
vCISO / Security Advisory Onboarding call Ongoing €125–150/hr Add-on

Get Started

Ready to book an engagement?

Get in touch to discuss scope, timeline, and pricing. Most engagements can start within one week of sign-off.

Or email: info@cyberscore.nl — response within 24 hours on business days.