What your organisation exposes to the outside world, and how to find and prioritise vulnerabilities before an attacker does.
Published on July 11, 2026
A scan report with dozens of findings: what comes first? EPSS predicts the likelihood of exploitation, the KEV catalogue shows confirmed exploitation. This is how you prioritise by actual risk instead of severity scores alone.
Read article →Published on July 11, 2026
A penetration test and a vulnerability scan are not synonyms. What is the difference, what do they cost, what does NIS2 expect and in what order should you deploy them? A guide for boards and decision-makers.
Read article →Published on July 11, 2026
Vulnerability monitoring is the continuous surveillance of your systems for vulnerabilities. Why does a one-off scan or pentest age so quickly, what does NIS2 expect, and what should you demand from good monitoring?
Read article →Published on July 3, 2026
internet.nl is an excellent free starting point for modern internet standards. But a snapshot is not an evidence file. When a free check is enough, and when it is not.
Read article →Published on June 16, 2026
Your external attack surface changes constantly. What External Attack Surface Management (EASM) is, why SMEs and the supplier chain need it, and how to manage it with evidence.
Read article →Published on June 16, 2026
OpenKAT is a free, open-source vulnerability analysis tool, originally built by the Dutch Ministry of Health and now maintained by the community. Not a mandatory SaaS, not a certification.
Read article →Published on June 12, 2026
Shadow IT is the biggest blind spot under NIS2. Learn how to manage your external attack surface: prevent subdomain takeover, find exposed admin panels and track down expired certificates with continuous monitoring.
Read article →Published on May 19, 2026
Your attack surface in plain English: DNS, open ports, TLS, subdomains, exposed panels and CVEs. What an attacker sees and why monitoring matters.
Read article →