Essential Care
From €149 / month
- Monthly external vulnerability scan (agreed scope)
- Simple “traffic light” risk summary
- Email support for clarification
Ideal for: Small websites and early-stage businesses.
Most small businesses don’t get “targeted”. They get hit by automated scanning, reused exploits, weak credentials, and simple misconfigurations. My job is to show you what’s exposed, what matters most, and what to fix first — without burying you in jargon.
If you’re unsure what you need, start with a quick check. You’ll get a clear direction in minutes — not weeks.
Run the Free Scanner Book a 15-min Scope Call
No long contracts. No “mystery” deliverables. You’ll know exactly what you’re getting before anything starts.
Pick what sounds closest to your situation. I’ll recommend the best starting point and what you’ll get.
Choose a focused test when you have a specific target, or use a care plan if you want ongoing visibility. Most SMBs get the best value by starting focused, then moving into a monthly plan.
For websites, client portals, dashboards, and web apps. This is where most real-world breaches begin.
Outcome: a prioritized fix list + evidence so your devs can act immediately.
Typical range: €350 – €900 (small sites), €900 – €1,800 (larger/complex).
APIs power mobile apps, integrations, and partner access — and they’re often wide open without anyone noticing.
Outcome: blocked abuse paths + clear remediation steps by endpoint area.
Typical range: €450 – €1,200 depending on endpoints and auth complexity.
For external exposure, server misconfigurations, remote access, and internal lateral movement risks.
Outcome: reduce blast radius and remove easy entry points.
Typical range: €500 – €1,500 depending on hosts and internal vs external scope.
Security isn’t just technical. A single click or reused password can undo everything else. These tests are always authorized, controlled, and designed to improve, not embarrass.
Typical range: €250 – €750 (phishing), €750 – €1,400 (multi-step scenarios).
For businesses that want impact demonstrated realistically: objectives, attack paths, and true business risk.
Typical range: €1,200 – €3,500 depending on objectives and scope.
Testing is pointless if it doesn’t translate into action. You get a clear roadmap and support to execute it.
Included with every engagement. Retesting typically €150 – €450 depending on scope.
One-off pentests are a strong start. But exposure changes weekly: plugins update, staff change, new systems get added. Care plans give you ongoing visibility and a simple, repeatable way to stay ahead — without hiring a full security team.
It’s the best balance of regular scanning, deeper review, and fix prioritization — without enterprise overhead.
From €149 / month
Ideal for: Small websites and early-stage businesses.
From €249 / month
Ideal for: Growing teams with more than one public-facing system.
From €449 / month
Ideal for: Businesses that want a long-term technical security partner.
All pricing depends on scope and complexity. These ranges are a starting point — you’ll receive a tailored proposal before you commit to anything.
We agree targets, rules, time window, and what “done” looks like. No testing outside written authorization.
I validate issues with real evidence — not just scanner output — and focus on what’s actually exploitable.
You get a clear “fix first” roadmap: what matters now, what matters later, and how to reduce risk quickly.
After fixes, I verify critical items are actually closed. This is where many tests fail — I don’t skip it.
The internet is constantly scanned. Attackers don’t need to “hate” your business — they only need one exposed service, one weak login, or one unpatched component.
Internet-facing systems are scanned continuously by automated bots and commodity tools.
Weak passwords, reused credentials, and phishing are still the easiest entry points.
Public vulnerabilities are weaponized fast — unpatched systems stay valuable targets.
You shift from guessing and reacting to fixing the highest-risk issues first.
If you’re unsure what you need, run the free scan. If you already know what you want tested, book a short scope call.
No. Testing is controlled and scoped. I avoid disruptive actions unless explicitly approved.
Sometimes. Black-box testing checks what attackers see; authenticated testing finds deeper issues. We decide based on goals.
Depends on scope. Small web tests can be quick; larger systems take longer. You’ll get a timeline before we start.
Yes. Retesting is available and recommended for critical findings, especially if you need proof for stakeholders.