Available for new engagements · Remote worldwide

Find the weakness
before someone
else does.

A data breach now costs $4.44 million on average. I find your vulnerabilities before attackers do. Everything manual, by the same specialist, wherever your team is based, and the report is ready the next day.

Free intake Fixed price based on scope Retest included NDA as standard
OSCP eWPTxv2 MSc Cyber Security KvK 99738929
Scope
Web apps REST / GraphQL Network infra Authentication Authorisation Business logic
$4.44 mln
Global average cost of a data breach
Source: IBM Cost of a Data Breach Report 2025
181 days
Average time before a breach is discovered
Source: IBM Cost of a Data Breach Report 2025
1 tester
Same OSCP expert from intake to final report
OSCP Certified
eWPTxv2 Certified
MSc Cyber Security
Chamber of Commerce Registered
SOC 2 / ISO 27001 reporting
Response within 1 business day
Operating in the EU? NIS2 compliance is now mandatory.

Under the Dutch Cybersecurity Act implementing NIS2 (in force 15 August 2026, no transition period), organisations active in the Netherlands and the wider EU must demonstrate their cyber security. A penetration test report is the most widely accepted form of evidence for regulators. Outside the EU, the same report supports your SOC 2, ISO 27001 and PCI DSS audits.

Check your obligations →
Why now?

The real cost of a
security incident.

$4.44M

Global average cost of a data breach, including fines, reputational damage, customer loss and remediation costs.

IBM Cost of a Data Breach Report 2025
181 days

Average time before an organisation realises it has been breached. Months during which an attacker roams freely.

IBM Cost of a Data Breach Report 2025
88%

Of SMB breaches involve ransomware or extortion, versus 39% at large organisations. Smaller teams, with less IT capacity, are hit hardest.

Verizon Data Breach Investigations Report 2025 (SMB snapshot)
01 · What does Resync do?

Penetration testing
services.

WEB APP

Web Application Penetration Test

I attack your web application the way an attacker would. I test for OWASP Top 10, logic flaws and access control issues. The report describes per finding how it can be exploited and what your development team can do to fix it.

↳ Clarity on which vulnerabilities are genuinely exploitable
API & INFRA

Infrastructure & API Security

Your servers, networks and API endpoints are just as vulnerable as the application itself. I look for misconfigurations, exposed services and privilege escalation — things an IT administrator rarely encounters because they only become visible when thinking like an attacker.

↳ Overview of your full external attack surface
RETEST

Verification & Retest

Patching without verification is guesswork. After fixes are applied, I retest to confirm the vulnerabilities are actually resolved. You receive written confirmation you can use with regulators or management.

↳ Official proof of remediation, in writing
ADVISORY

Security Review & Advisory

Not ready for a full pentest yet, but want to know where you stand? Or unsure about the architecture of a new application? I review and give honest advice — including if the advice is that you don't need a test yet.

↳ Clear advice without having to buy a test immediately
Entry product

Security Quick Scan — one day, fixed price €1,000

One day of focused manual testing of your most important application, using the same approach as a full pentest. You get the key findings and concrete next steps, and you'll know whether — and where — a full pentest is needed. Need more days? The per-day rate goes down. Retest included.

Book a Quick Scan →
View our pentest service → Schedule free intake →
02 · Why Resync?

What you don't get
from a large agency.

Large pentest firm
  • High costs on daily or hourly rate — the final invoice is rarely what you expected
  • Waiting time of 2 to 6 months before you get scheduled
  • Different testers per phase — you don't know who is on your systems
  • Templated reports that a junior could produce
  • Retest? Separate quote, extra cost
  • Contact goes through an account manager, not the tester
✦ Resync
  • Fixed price based on scope — you know the cost upfront
  • Start within 1–2 weeks after quote approval
  • Always the same OSCP-certified senior tester, from intake to close
  • Bespoke report: executive summary and technical depth
  • Retest always included — no loose ends
  • Direct communication with the tester — no middleman
03 · About the specialist

Always the same
tester.

Resync deliberately has no account managers or junior staff. You work with the same person from start to finish. I don't outsource and don't involve anyone else.

I have worked with municipalities, healthcare organisations and educational institutions and understand what is at stake: personal data, legal obligations and continuity of service. That requires a different approach than a typical startup.

OSCP, eWPTxv2 and a Master's in Cyber Security are not just credentials. I can penetrate systems in ways that a scanner will never find — which is precisely what manual testing is about.

MSc Cyber Security
Master of Science in Cyber Security · academic background in attack detection, cryptography and risk management
OSCP
Offensive Security Certified Professional · hands-on system & network exploitation
eWPTxv2
eLearnSecurity Web App Penetration Tester eXtreme · advanced web application exploitation
Expertise
  • Web application pentesting (OWASP, PTES)
  • API security: REST, GraphQL, SOAP
  • Authentication & session management
  • Authorisation flaws & IDOR
  • Network & infrastructure security
  • Privilege escalation (Linux & Windows)
  • Reporting for both technical teams and executives
  • NIS2 & GDPR context for public sector
04 · Sectors

For organisations that can't afford a breach.

01

SaaS & Fintech

SOC 2 / ISO 27001

A pentest isn't formally required for SOC 2 or ISO 27001, but auditors expect one as evidence (CC4.1, Annex A 8.8 and 8.29). Sell to a financial institution? Since 2025, DORA requires them to secure annual testing evidence from suppliers like you. My report maps findings directly to those requirements. SOC 2 & ISO 27001 →

02

Healthcare & Healthtech

Patient data at stake

EHR platforms, patient portals and connected devices hold some of the most sensitive data there is. I test them the way a real attacker would, with HIPAA and GDPR expectations in mind.

03

E-commerce & Payments

PCI DSS

Checkout flows, payment integrations and customer accounts are a constant target. A penetration test supports your PCI DSS obligations and keeps fraud off your platform.

04

Startups & Vibe-Coded Apps

Cursor / Bolt / Lovable

Apps built with Cursor, Bolt or Lovable contain predictable vulnerabilities: IDOR, exposed API keys, missing endpoint authorisation. Scanners rarely catch them, manual testing does. Dedicated offer →

05

EU & NL Compliance

NIS2 · GDPR

Organisations operating in the Netherlands and the EU must now demonstrate their security under NIS2. A penetration test report is the evidence regulators, and your European customers, ask for.

06

Professional Services

Sensitive files, lean IT

Law firms, agencies and advisors hold highly confidential client data with limited in-house IT. Large-firm pricing is out of reach; I offer a fixed-price alternative.

05 · Approach

You know the cost upfront
and the findings afterwards.

  1. No-obligation intake

    Free discovery call. What is in scope, what do you need to know, what is off-limits — everything on paper before we agree to anything.

    Day 1
  2. Fixed-price quote

    You know the cost and deliverables upfront. No hourly billing, no hidden overruns.

    Day 2–3
  3. Manual pentest

    Fully manual execution. Not an automated scanner you could run yourself.

    Week 1–2
  4. Clear report

    Executive summary and technical findings with reproduction steps. Useful for both the CISO and the board.

    End week 2
  5. Retest included

    After patching, I verify that findings are genuinely resolved. Only then do I close the engagement.

    Post-patching
Request free intake →

No obligations · Response within 1 business day

Frequently asked questions

Answers to your
most important questions.

How much does a penetration test cost?

All quotes at Resync are fixed prices. You know exactly what you pay upfront, no surprises. A single-day focused session starts around €1,000, billed in EUR, USD or GBP. A full web app pentest of 3 to 5 days is cheaper per day the more scope you include. Send a request via the contact form and you'll hear within one business day what to expect.

Do you work with clients outside the Netherlands?

Yes. Almost every engagement runs fully remotely, so where you are based is rarely a constraint. I work with clients across the EU, the UK and the US, arrange calls around your timezone, sign an NDA and contract in English, and can invoice in EUR, USD or GBP. Reporting and communication are in English throughout.

How long does a penetration test take?

A web application penetration test takes an average of 3 to 5 working days. Infrastructure tests vary based on scope. After intake you receive an exact schedule. Total turnaround from intake to final report is typically 1 to 3 weeks.

We are a small organisation — do we really need a pentest?

Small and medium organisations are a popular target because attackers know there is less security capacity. NIS2 also requires an increasing number of organisations — including SMEs and public sector entities — to demonstrably have their security in order.

A pentest is relevant for any organisation that handles confidential data or is legally required to demonstrate it takes security seriously.

What if little or nothing is found?

Then you have written proof that your systems withstood a manual attack by a certified tester. That is also a valuable result — for regulators, clients or your own board.

How confidentially is my information handled?

All findings, system documentation and communications are subject to strict confidentiality. A standard NDA is signed for every project. Your data is never shared or stored outside the project.

We already have an IT team or IT partner — do we still need a pentest?

Yes. Your IT partner manages your systems, but doesn't think like an attacker. Most vulnerabilities I find are not visible to routine IT management because they are discovered by creatively misusing logic and configurations in ways that never arise during normal operations.

Ready to start?

The longer you wait,
the more time an attacker has.

One conversation is enough to clarify whether and how I can help. Free, no obligation and a response within one business day.

Currently available for new engagements
Free intake Fixed price based on scope Retest included NDA as standard
Contact

Start today,
free and without obligation.

Tell me in a few sentences about your application or question. I respond within one business day and won't send a quote unless you want one.

LinkedIn Sofyan Aarrass
Location Based in the Netherlands · Remote worldwide
Availability Available for new engagements

Times shown in your local time · 60-minute call

Can't find a time that works? Send a message instead — we'll figure something out together.

Thanks — your intake call is booked. You'll receive a confirmation by email.