Available for new engagements · Netherlands

Find the weakness
before someone
else does.

A data breach costs an average of €4.5 million. I find your vulnerabilities before attackers do. Everything manual, by the same specialist, and the report is ready for your team the next day.

Free intake Fixed price based on scope Retest included NDA as standard
OSCP eWPTxv2 MSc Cyber Security KvK 99738929
Scope
Web apps REST / GraphQL Network infra Authentication Authorisation Business logic
€4.5 mln
Average cost of a data breach in Europe
Source: IBM Cost of a Data Breach Report 2024
194 days
Average time before a breach is discovered
Source: IBM Security 2024
1 tester
Same OSCP expert from intake to final report
OSCP Certified
eWPTxv2 Certified
MSc Cyber Security
Chamber of Commerce Registered
NIS2-Ready Reporting
Response within 1 business day
NIS2 is in force. Can you demonstrate compliance?

Municipalities, healthcare organisations and critical-sector entities are legally required to demonstrate their cyber security. A pentest report is the most widely accepted form of evidence for regulators.

Check your obligations →
Why now?

The real cost of a
security incident.

€4.5M

Average cost of a data breach in Europe, including fines, reputational damage, customer loss and remediation costs.

IBM Cost of a Data Breach Report 2024
194 days

Average time before an organisation realises it has been breached. Months during which an attacker roams freely.

IBM Security 2024
43%

Of all cyber attacks target SMEs and the public sector. Less IT capacity means a higher chance of success for an attacker.

Verizon Data Breach Investigations Report 2024
01 · What does Resync do?

Penetration testing
services.

WEB APP

Web Application Penetration Test

I attack your web application the way an attacker would. I test for OWASP Top 10, logic flaws and access control issues. The report describes per finding how it can be exploited and what your development team can do to fix it.

↳ Clarity on which vulnerabilities are genuinely exploitable
API & INFRA

Infrastructure & API Security

Your servers, networks and API endpoints are just as vulnerable as the application itself. I look for misconfigurations, exposed services and privilege escalation — things an IT administrator rarely encounters because they only become visible when thinking like an attacker.

↳ Overview of your full external attack surface
RETEST

Verification & Retest

Patching without verification is guesswork. After fixes are applied, I retest to confirm the vulnerabilities are actually resolved. You receive written confirmation you can use with regulators or management.

↳ Official proof of remediation, in writing
ADVISORY

Security Review & Advisory

Not ready for a full pentest yet, but want to know where you stand? Or unsure about the architecture of a new application? I review and give honest advice — including if the advice is that you don't need a test yet.

↳ Clear advice without having to buy a test immediately
View our pentest service → Schedule free intake →

One-day session from €1,000 · multi-day engagements lower per day · retest included

02 · Why Resync?

What you don't get
from a large agency.

Large pentest firm
  • High costs on daily or hourly rate — the final invoice is rarely what you expected
  • Waiting time of 2 to 6 months before you get scheduled
  • Different testers per phase — you don't know who is on your systems
  • Templated reports that a junior could produce
  • Retest? Separate quote, extra cost
  • Contact goes through an account manager, not the tester
✦ Resync
  • Fixed price based on scope — you know the cost upfront
  • Start within 1–2 weeks after quote approval
  • Always the same OSCP-certified senior tester, from intake to close
  • Bespoke report: executive summary and technical depth
  • Retest always included — no loose ends
  • Direct communication with the tester — no middleman
03 · About the specialist

Always the same
tester.

Resync deliberately has no account managers or junior staff. You work with the same person from start to finish. I don't outsource and don't involve anyone else.

I have worked with municipalities, healthcare organisations and educational institutions and understand what is at stake: personal data, legal obligations and continuity of service. That requires a different approach than a typical startup.

OSCP, eWPTxv2 and a Master's in Cyber Security are not just credentials. I can penetrate systems in ways that a scanner will never find — which is precisely what manual testing is about.

MSc Cyber Security
Master of Science in Cyber Security · academic background in attack detection, cryptography and risk management
OSCP
Offensive Security Certified Professional · hands-on system & network exploitation
eWPTxv2
eLearnSecurity Web App Penetration Tester eXtreme · advanced web application exploitation
Expertise
  • Web application pentesting (OWASP, PTES)
  • API security: REST, GraphQL, SOAP
  • Authentication & session management
  • Authorisation flaws & IDOR
  • Network & infrastructure security
  • Privilege escalation (Linux & Windows)
  • Reporting for both technical teams and executives
  • NIS2 & GDPR context for public sector
04 · Sectors

For organisations that can't afford a breach.

01

Municipalities

NIS2 obligation

Citizen portals, internal applications and chain systems. Municipalities are legally required to demonstrably have their security in order under the Cybersecurity Act.

02

Healthcare

High urgency

EHR systems, patient portals and medical devices on the network. NEN 7510 requires demonstrable information security — a pentest is the standard form of evidence.

03

Education

Sensitive student data

Student registration systems and portals at schools and universities. IBP frameworks require demonstrable security for personal data.

04

Legal & Notarial

Underserved, high risk

Extremely sensitive files, limited IT capacity. Large agency prices are beyond reach for small firms — Resync offers a fixed-price alternative.

05

Fintech & SaaS

SOC 2 / ISO 27001

Scale-ups pursuing SOC 2 or ISO 27001 won't pass the audit process without a pentest report. I ensure the report aligns with the requirements.

06

Vibe-Coded Startups

Cursor / Bolt / Lovable

Apps built with Cursor, Bolt or Lovable contain predictable vulnerabilities: IDOR, exposed API keys, missing endpoint authorisation. Scanners rarely catch them — manual testing does. Dedicated offer →

05 · Approach

You know the cost upfront
and the findings afterwards.

  1. No-obligation intake

    Free discovery call. What is in scope, what do you need to know, what is off-limits — everything on paper before we agree to anything.

    Day 1
  2. Fixed-price quote

    You know the cost and deliverables upfront. No hourly billing, no hidden overruns.

    Day 2–3
  3. Manual pentest

    Fully manual execution. Not an automated scanner you could run yourself.

    Week 1–2
  4. Clear report

    Executive summary and technical findings with reproduction steps. Useful for both the CISO and the board.

    End week 2
  5. Retest included

    After patching, I verify that findings are genuinely resolved. Only then do I close the engagement.

    Post-patching
Request free intake →

No obligations · Response within 1 business day

Frequently asked questions

Answers to your
most important questions.

How much does a penetration test cost?

All quotes at Resync are fixed prices. You know exactly what you pay upfront, no surprises. A single-day focused session starts around €1,000. A full web app pentest of 3–5 days is cheaper per day the more scope you include. Send a request via the contact form and you'll hear within one business day what to expect.

How long does a penetration test take?

A web application penetration test takes an average of 3 to 5 working days. Infrastructure tests vary based on scope. After intake you receive an exact schedule. Total turnaround from intake to final report is typically 1 to 3 weeks.

We are a small organisation — do we really need a pentest?

Small and medium organisations are a popular target because attackers know there is less security capacity. NIS2 also requires an increasing number of organisations — including SMEs and public sector entities — to demonstrably have their security in order.

A pentest is relevant for any organisation that handles confidential data or is legally required to demonstrate it takes security seriously.

What if little or nothing is found?

Then you have written proof that your systems withstood a manual attack by a certified tester. That is also a valuable result — for regulators, clients or your own board.

How confidentially is my information handled?

All findings, system documentation and communications are subject to strict confidentiality. A standard NDA is signed for every project. Your data is never shared or stored outside the project.

We already have an IT team or IT partner — do we still need a pentest?

Yes. Your IT partner manages your systems, but doesn't think like an attacker. Most vulnerabilities I find are not visible to routine IT management because they are discovered by creatively misusing logic and configurations in ways that never arise during normal operations.

Ready to start?

The longer you wait,
the more time an attacker has.

One conversation is enough to clarify whether and how I can help. Free, no obligation and a response within one business day.

Currently available for new engagements
Free intake Fixed price based on scope Retest included NDA as standard
Contact

Start today,
free and without obligation.

Tell me in a few sentences about your application or question. I respond within one business day and won't send a quote unless you want one.

LinkedIn Sofyan Aarrass
Location Netherlands · Remote & On-site
Availability Available for new engagements

Response within 1 business day · No obligations · NDA as standard

Thank you for your request. I will respond within one business day.