ICT security assessment
An ICT security assessment systematically maps the vulnerabilities and risks in your application or ICT environment, and delivers a report with risk classification and remediation measures. It is often part of a tender or RFI, where a client wants to know how your security stands before selecting you. Appfront carries out the assessment and can also fix the vulnerabilities found.
What is an ICT security assessment?
An ICT security assessment is a structured review of the vulnerabilities and risks in an application, system or ICT environment. It typically combines an automated vulnerability scan, which quickly gives a broad picture based on version numbers and known signatures, with a risk analysis that weighs the weaknesses found against the impact on your organisation. Where needed, we add a penetration test: an ethical hacker actively tries to exploit vulnerabilities to show what an attacker could achieve in practice.
That distinction matters: a vulnerability scan is largely automated and gives an initial picture, while a pentest is mostly manual work by an experienced specialist and goes deeper. For most tenders and RFIs, a combination of both, resulting in a clear report, is exactly what a client asks for. More background on this distinction can be found at the Nationaal Cyber Security Centrum.
An ICT security assessment is something different from building an integration with a specific government service such as DigiD: that is a technical integration, whereas this assessment looks at how secure your wider ICT environment is, regardless of which integrations it contains.
Vulnerability scan
An automated scan that quickly gives a broad picture of possible weak points based on versions and known signatures.
Risk analysis
Each finding is weighed by impact and likelihood, so you know what needs fixing first.
Reporting & remediation measures
A readable report with prioritisation, suitable for both your technical team and a contracting authority.
A regulated test under DORA follows fixed phases, fixed roles and a delivery to the authority. We cover that on the page about software for the TLPT process.
How an ICT security assessment works
We define the scope based on your goal: a broad overview, an in-depth penetration test, or a report that meets the requirements of a specific tender.
Together we decide which systems, applications and integrations are included, and against which standard we test: ISO 27001, the BIO, or both.
We carry out a vulnerability scan and, where relevant, a penetration test following the OWASP guidelines for web applications.
Each finding receives a risk classification based on impact and likelihood, so prioritisation is clear.
You receive a report with remediation measures. If we carry out those measures, a retest to confirm them can follow if you wish.
What an ICT security assessment involves in practice
We tailor the exact scope to your goal and the requirements of your client or tender.
Vulnerability scan
Automated scanning for known vulnerabilities in the software, versions and configurations of your application and infrastructure.
Penetration testing
Manual testing in which we actively attempt to exploit vulnerabilities in web and mobile applications, following the OWASP guidelines.
Risk analysis & classification
Each finding is weighed by impact and likelihood, with clear prioritisation for follow-up.
Reporting for tenders or RFIs
A report that meets what contracting authorities and clients ask for, readable for both technical and procurement teams.
Implementing remediation measures
We also fix the vulnerabilities we find in your application, rather than only delivering a report.
Retest
After implementing measures, we use a retest to confirm that the vulnerabilities found have actually been resolved.
Who an ICT security assessment is for
Especially relevant for organisations where trust in security must be demonstrable.
Government & contracting authorities
Organisations that, as clients, require a current security assessment from their suppliers, or that must themselves demonstrate compliance with the BIO.
Healthcare & financial sector
Sectors under heightened compliance pressure, where clients, regulators or customers expect demonstrable security.
Scale-ups ahead of a major client audit
Growing businesses looking to win an enterprise client that first need to demonstrate their own security is in order.
Organisations following an incident
Companies that, after a security incident, want to understand how the vulnerability arose and which measures will prevent recurrence.
Frameworks and approach
We test against the standard that fits your situation. If you are working on a public sector tender, also see our pages on tendering for custom software and building BIO-compliant software: the latter covers building a BIO-compliant system, whereas this assessment is the investigation of vulnerabilities and risks itself.
Why choose Appfront for an ICT security assessment?
We don't just assess, we also build. If we find a vulnerability, we can fix it directly in your application rather than leaving you with only a report.
We write the report so that both your technical team and a contracting authority or client understand the outcome, with clear prioritisation instead of a long list of technical findings without context.
Also take a look at our broader approach to custom software development and, for the public sector, procuring custom software.
- Assessment and resolution of identified vulnerabilities
- Assessment against ISO 27001 or the BIO, according to what your situation requires
- Penetration testing in line with OWASP guidelines
- Reporting suitable for both technical teams and tender processes
- Retesting after remediation measures have been implemented
- Experience with both private and public sector clients
Handling discovered vulnerabilities with care
Findings from a security assessment are sensitive information. We only share vulnerabilities with the people at your organisation who need to know, we record confidentiality in our collaboration agreements, and we work in line with the principles of responsible vulnerability disclosure, as described in our CVD policy.
You can read more about how we approach information security in our information security policy. Questions about your specific situation? Get in touch with us.
- Confidential handling of findings
- Responsible vulnerability disclosure (CVD)
- Reports shared only with authorised persons
- Clear agreements on confidentiality from the outset
Frequently asked questions about an ICT security assessment
Answers to the questions we are asked most often.
A pentest is one specific form of investigation within a broader ICT security assessment: an ethical hacker actively attempts to exploit vulnerabilities to show what an attacker could achieve. An ICT security assessment is broader and typically combines an automated vulnerability scan, a risk analysis of your environment and, where relevant, a pentest, culminating in a report with prioritised recommendations and remediation measures.
Contracting authorities and large clients increasingly ask for a current security assessment, or a statement that your software complies with a standard such as ISO 27001 or the BIO, before they select a supplier. Whether it is mandatory varies by tender and client; we help you deliver an assessment that matches what is being asked.
We assess your application and environment against the framework that fits your situation: ISO 27001 for general information security, or the Baseline Information Security for Central Government (BIO) if you work with the public sector. We do not claim certification of our own, but we provide a report that lets you demonstrate where you stand against the framework.
You receive a report detailing the vulnerabilities found, a risk classification for each finding and concrete remediation measures, written so that both your technical team and a client or contracting authority can understand the outcome.
Yes. Alongside the assessment, we can also fix the vulnerabilities we find in your application and, if you wish, perform a retest to confirm the findings have been resolved.
When building BIO-compliant software, we develop a new system that meets the BIO from the architecture up. An ICT security assessment is the investigation itself: the evaluation of an existing or new environment for vulnerabilities and risks, often as a standalone project or as a requirement in a tender. If you are working on a new BIO-compliant system, also see our page on building BIO-compliant software.
Yes, for web applications we test against, among others, the well-known risk categories of the OWASP Top 10, such as injection vulnerabilities, insecure authentication and misconfigured access control.
Yes. After an incident, an assessment helps determine how the vulnerability arose, whether there are further weak points, and which measures are needed to prevent recurrence.
Ready for an ICT security assessment?
Tell us what prompted it: a tender, a recurring compliance requirement or an incident. Together we define the scope, carry out the assessment and, if you wish, help resolve what we find. If the assessment shows that your email authentication falls short, see DMARC and DNSSEC monitoring.