Vulnerability Assessment

Zie uw kwetsbaarheden, vóórdat een aanvaller ze ziet.

Met een Vulnerability Assessment brengt OranjeRaksha gestructureerd in kaart waar uw systemen, netwerken, cloudomgevingen en applicaties kwetsbaar zijn – in begrijpelijke taal, vertaald naar concrete risico’s en oplossingen.

Geen lijst met technische meldingen, maar een helder verhaal: wat is er kwetsbaar, waarom, wat kan er misgaan en wat moet u als eerste aanpakken.

Vulnerability Assessment

See your vulnerabilities before attackers do.

Through a Vulnerability Assessment, OranjeRaksha systematically reveals where your systems, networks, cloud environments and applications are weak – in clear language, translated into real risks and concrete actions.

Not just a list of technical issues, but a clear story: what is vulnerable, why, what could go wrong and what you should address first.

Systemen & netwerken Cloud & identity Web & API-beveiliging Systems & networks Cloud & identity Web & API security

Wat is een Vulnerability Assessment?

What is a Vulnerability Assessment?

Een Vulnerability Assessment is een uitgebreid technisch onderzoek naar zwakke plekken in uw systemen, netwerken, cloud en applicaties. Het doel is eenvoudig: weten waar u kwetsbaar bent, voordat iemand anders dat weet.

A Vulnerability Assessment is a thorough technical examination of weaknesses in your systems, networks, cloud environments and applications. The goal is simple: know where you are vulnerable before someone else does.

We analyseren waar kwetsbaarheden zitten, waarom ze er zijn en hoe ze misbruikt kunnen worden — en vertalen dit naar concrete risico's voor uw organisatie. “iets mis” is, maar vooral waar kwetsbaarheden zich bevinden, waarom ze er zijn, hoe ze misbruikt kunnen worden en wat de impact op uw organisatie kan zijn. Vergelijk het met een veiligheidskeuring van een gebouw: fundering, elektra, brandveiligheid – maar dan voor uw digitale omgeving.

We do not just check “if something is wrong”, but focus on where vulnerabilities exist, why they are there, how they can be exploited and what the impact could be on your organisation. Think of it as a safety inspection of a building – but for your digital infrastructure.

We brengen verouderde software, ontbrekende patches, verkeerde configuraties en onveilige cloudinstellingen in kaart — de meest voorkomende oorzaken van incidenten.,

We identify outdated software, missing patches, misconfigurations and insecure cloud configurations — the most common root causes of data breaches and security incidents.

Waarom is het belangrijk?

Why is it important?

De meeste incidenten beginnen niet met een spectaculaire hack, maar met iets kleins: een vergeten update, een verkeerde instelling, een testomgeving die nooit is opgeruimd of een cloud-resource die per ongeluk openbaar staat.

Most incidents do not start with a sophisticated attack, but with something small: a missed patch, a bad configuration, a forgotten test system or a cloud resource that was accidentally exposed.

Kleine kwetsbaarheden leiden tot grote gevolgen: datalekken, ransomware, systeemuitval en boetes. Een Vulnerability Assessment brengt de echte risico's in kaart — geprioriteerd op impact. en reputatieverlies.

Small vulnerabilities lead to serious consequences: data breaches, ransomware, system outages and fines. A Vulnerability Assessment maps the real risks — prioritised by impact — so you know exactly what to address first.

Voor organisaties die afhankelijk zijn van IT of cloud is een Vulnerability Assessment geen luxe — het is een directe bouwsteen richting NIS2 en ISO 27001 compliance.

For organisations that depend on IT or cloud, a Vulnerability Assessment is not a luxury — it is a direct building block towards NIS2 and ISO 27001 compliance.

Voor wie
Who Is This For?

Voor wie is dit?

Who is this for?

Een Vulnerability Assessment is relevant voor elke organisatie die afhankelijk is van IT, cloud of digitale diensten.

A Vulnerability Assessment is relevant for any organisation that depends on IT, cloud or digital services.

👨‍💼
CTO / IT Manager
CTO / IT Manager

Wil een helder, geprioriteerd beeld van technisch risico over systemen en cloud vóór de volgende boardrapportage.

Gets a clear, prioritised picture of technical risk across systems and cloud before the next board update.

📋
Compliance Officer
Compliance Officer

Heeft bewijs van beveiligingscontroles nodig voor NIS2, ISO 27001 of sectorspecifieke regelgeving.

Needs documented evidence of security controls for NIS2, ISO 27001 or sector-specific regulatory requirements.

🔍
Internal Auditor
Internal Auditor

Zoekt een onafhankelijke, auditwaardige beoordeling voor interne audit of risicorapportage.

Needs an independent, audit-grade assessment to support internal audit or risk management reporting.

🏢
Risk Manager
Risk Manager

Vertaalt cyberrisico naar het risicoregister van de organisatie met gekwantificeerde, geprioriteerde bevindingen.

Maps cyber risk to the organisation's risk register using quantified, prioritised findings.

🤝
Inkoop & Leveranciersteams
Procurement & Vendor Teams

Beoordeelt de securitypositie van een leverancier als onderdeel van third-party risk of due diligence.

Assesses a supplier's security posture as part of third-party risk or due diligence processes.

🚀
Scale-ups & MKB
Scale-ups & SMEs

Zet de eerste gestructureerde stap naar volwassen cybersecurity met een praktische, uitvoerbare nulmeting.

Takes the first structured step towards mature cybersecurity with a practical, actionable baseline assessment.

Praktijkvoorbeelden uit de echte wereld

Real-world examples

Twee publieke incidenten laten goed zien waarom inzicht in kwetsbaarheden essentieel is – en hoe een Vulnerability Assessment dit eerder had kunnen blootleggen.

Two public incidents clearly show why visibility into vulnerabilities matters – and how a Vulnerability Assessment could have exposed issues sooner.

Case 1: Softwarecomponent
Case 1: Software component
Log4j (Log4Shell): één library, wereldwijde impact
Log4j (Log4Shell): one library, global impact

De Log4j-kwetsbaarheid liet zien hoe één veelgebruikte library wereldwijd miljoenen systemen in gevaar kon brengen. Veel organisaties wisten niet in welke applicaties en systemen deze component precies gebruikt werd, waardoor het moeilijk was om snel en gericht te reageren.

The Log4j vulnerability showed how a single widely used library could put millions of systems at risk. Many organisations did not know exactly where this component was used, making it hard to respond quickly and effectively.

Bij een Vulnerability Assessment van OranjeRaksha kijken we niet alleen naar “het systeem”, maar ook naar gebruikte componenten, afhankelijkheden en versies. Zo ontstaat een duidelijk beeld van exposure en kwetsbare bouwstenen.

In a Vulnerability Assessment by OranjeRaksha, we do not only look at “the system”, but also at components, dependencies and versions. This creates a clear picture of exposure and vulnerable building blocks.

Case 2: Cloud misconfiguratie
Case 2: Cloud misconfiguration
Capital One (AWS): fout in IAM en configuratie
Capital One (AWS): IAM and configuration issue

Bij het Capital One-incident speelde een verkeerde combinatie van rechten (IAM), netwerkconfiguratie en toegang tot metadata een grote rol. Het resultaat: een grootschalig datalek via de cloud-infrastructuur.

In the Capital One incident, a combination of IAM permissions, network configuration and access to metadata played a key role. The result: a large-scale data breach via the cloud infrastructure.

In onze Vulnerability Assessment beoordelen we daarom niet alleen patches en versies, maar ook cloudrechten, toegangsstructuren en configuraties. We kijken naar wat er kan gebeuren als iemand misbruik maakt van een zwakke plek – en hoe u dat voorkomt.

In our Vulnerability Assessment, we therefore look beyond patches and versions and also assess cloud permissions, access structures and configurations. We consider what could happen if someone exploits a weakness – and how to prevent that.


Scope & dekking
Scope & Coverage

Wat valt typisch in scope?

What is typically in scope?

Scope wordt altijd vooraf afgesproken. Onderstaand overzicht toont wat een standaard opdracht dekt – en wat erbuiten valt.

Scope is always agreed upfront. Below is what a standard engagement covers – and what falls outside it.

Typisch in scope
Typically in scope
Interne netwerkinfrastructuur & serversInternal network infrastructure & servers
Cloudomgevingen (AWS, Azure, GCP)Cloud environments (AWS, Azure, GCP)
Webapplicaties & publieke API'sWeb applications & public-facing APIs
Identity & toegangsbeheer (IAM)Identity & access management (IAM)
Firewall & netwerksegmentatieFirewall & network segmentation
Patchniveaus & softwareversiesPatch levels & software versions
Cloudopslag & configuratiepostureCloud storage & configuration posture
Derde partij integraties (op verzoek)Third-party integrations (on request)
Typisch buiten scope
Typically out of scope
Fysieke toegangstests — zie Physical Security ReviewPhysical access testing — see Physical Security Review
Social engineering & phishing (zie Penetration Testing)Social engineering & phishing (see Penetration Testing)
OT/SCADA-systemen — zie OT Security AuditOT/SCADA systems — see OT Security Audit
Externe SaaS-platforms niet in eigendom van klantThird-party SaaS platforms not owned by client
Destructief testen of exploituitvoeringDestructive testing or exploit execution
Systemen buiten overeengekomen IP/domeinbereikenSystems outside agreed IP / domain ranges

Wat u ontvangt
What you receive

Wat ontvangt u?

What you receive

Elke Vulnerability Assessment levert een compleet, auditklaar pakket op – geen ruwe scanoutput, maar bruikbare inzichten.

Every Vulnerability Assessment delivers a complete, audit-ready package – not just a raw scan output, but actionable insights.

📄
Managementsamenvatting
Executive Summary

Boardklaar overzicht van risicoposture, kernbevindingen en aanbevolen prioriteiten – geschreven voor niet-technische stakeholders.

Board-ready overview of risk posture, key findings and recommended priorities – written for non-technical stakeholders.

🔍
Technisch bevindingsrapport
Technical Findings Report

Gedetailleerde documentatie per bevinding: beschrijving, bewijs, CVSS-score, getroffen asset en herstelstappen.

Detailed per-finding documentation: description, evidence, CVSS score, affected asset and remediation steps.

📊
Risicoprioriteitenlijst
Risk-rated Priority List

Alle bevindingen gerangschikt op risiconiveau (Kritiek / Hoog / Gemiddeld / Laag) met businessimpactcontext.

All findings ranked by risk level (Critical / High / Medium / Low) with business impact context.

🗺️
Verbeteringsroadmap
Remediation Roadmap

Gefaseerd actieplan: quick wins, kortetermijnfixes en structurele verbeteringen op langere termijn.

Phased action plan: quick wins, short-term fixes and longer-term structural improvements.

🤝
Debrief & teamsessie
Debrief & Team Session

Live walkthrough met uw IT-, security- of auditteam – vragen beantwoord, prioriteiten afgestemd.

Live walkthrough with your IT, security or audit team – questions answered, priorities aligned.

🔁
Optionele retest
Optional Retest

Na herstel bevestigt een gerichte retest dat kritieke bevindingen effectief zijn opgelost.

After remediation, a targeted retest confirms that critical findings have been effectively resolved.

Onze aanpak

Our approach

Onze aanpak is ontworpen om kwetsbaarheden niet alleen te vinden, maar ook daadwerkelijk opgelost te krijgen – met duidelijke prioriteiten, heldere rapportage en begeleiding bij de uitvoering.

Our approach is designed not just to identify vulnerabilities, but to ensure they are actually resolved – with clear priorities, transparent reporting and support during remediation.

1
Stap 1
Step 1
Scoping & voorbereiding
Scoping & preparation

Samen bepalen we wat in scope is: systemen, netwerken, cloudomgevingen en applicaties. We bespreken uw businessdoelen, kritieke processen en afhankelijkheden.

Together we define what is in scope: systems, networks, cloud environments and applications. We discuss your business goals, critical processes and dependencies.

IP-bereiken Cloudaccounts Tijdvensters IP ranges Cloud accounts Time windows
2
Stap 2
Step 2
Technische Vulnerability Assessment
Technical Vulnerability Assessment

Grondige analyse van systemen, netwerken, cloudconfiguraties en applicaties met bewezen tooling. Geautomatiseerde scans aangevuld met gerichte handmatige controles.

In-depth analysis of systems, networks, cloud configurations and applications using proven tools. Automated scanning combined with targeted manual checks.

Kwetsbaarheden Cloudinstellingen IAM-controle Vulnerabilities Cloud config IAM review
3
Stap 3
Step 3
Handmatige validatie
Manual validation

Belangrijke bevindingen worden handmatig gevalideerd. We controleren of kwetsbaarheden daadwerkelijk aanwezig en misbruikbaar zijn.

Important findings are manually validated. We check whether vulnerabilities are truly present and exploitable.

False positives verwijderd Ketenanalyse False positives removed Chain analysis
4
Stap 4
Step 4
Risico & impact
Risk & impact

We vertalen technische data naar businessrisico's: beschikbaarheid, vertrouwelijkheid, integriteit, reputatie en compliance.

We translate technical data into business risks: availability, confidentiality, integrity, reputation and compliance.

CVSSNIS2ISO 27001
5
Stap 5
Step 5
Hardening & verbeteradvies
Hardening & improvement advice

Concrete quick wins en structurele verbeteringen: van configuratiewijzigingen en segmentatie tot beter patchmanagement, logging en monitoring.

Concrete quick wins and structural improvements: from configuration changes and segmentation to better patch management, logging and monitoring.

Quick wins Roadmap Lange termijn Quick wins Roadmap Long-term
6
Stap 6
Step 6
Rapportage, follow-up & begeleiding
Reporting, follow-up & guidance

U ontvangt een auditwaardig rapport met managementsamenvatting, details, prioriteiten en roadmap. Daarna blijven we betrokken.

You receive an audit-grade report with executive summary, details, priorities and roadmap. We then stay engaged.

Managementsamenvatting Retest optioneel Executive summary Retest option

Gevoelige informatie wordt met de grootst mogelijke zorgvuldigheid behandeld tijdens het assessment en veilig vernietigd na de retentieperiode.

Sensitive information is handled with utmost care during the assessment and securely destroyed after the retention period.

Wilt u weten hoe uw kwetsbaarheden eruitzien in de praktijk? Deel uw omgeving en we plannen een korte intake om de scope van een Vulnerability Assessment te bepalen.

Want to understand what your vulnerabilities look like in practice? Share your environment details and we will define the scope of a tailored Vulnerability Assessment.

Vraag uw Vulnerability Assessment aan Request Your Vulnerability Assessment

Geen verplichtingen. Wij reageren doorgaans binnen 1 werkdag. No commitment. We typically respond within 1 business day.

Veelgestelde vragen
Frequently Asked Questions

Veelgestelde vragen

Frequently Asked Questions


Gerelateerde diensten
Related services

Heeft u ook dit nodig?

You might also need

Een Vulnerability Assessment is vaak het startpunt – deze diensten gaan dieper of breder, afhankelijk van uw volgende prioriteit.

A Vulnerability Assessment is often the starting point – these services go deeper or broader depending on your next priority.