Lauren Verheyen

CRA calculator kmo

Wat kost CRA-compliance echt? Een calculator, een ongemakkelijk cijfer en twee subsidies

Sinds kort staat er online een CRA Compliance Cost Calculator. Je vult je productklasse in, je huidige beveiligingsmaturiteit en het aantal producten in scope, en je krijgt een indicatie van wat het kost om onder de Cyber Resilience Act compliant te geraken. Eenmalig en jaarlijks. Het is een handige tool om een gesprek te openen. […]

Wat kost CRA-compliance echt? Een calculator, een ongemakkelijk cijfer en twee subsidies Read More »

Focused shot of a laptop displaying code, suitable for tech and coding themes.

Black Box, Grey Box, White Box: How to Choose the Right Pentest Methodology

Most organizations pick a pentest methodology based on a misunderstanding. The box types – black, grey, white – don’t describe how much access testers get. They describe how much they know going in. It’s a small distinction with real consequences for what your test finds.  Black box  Testers start with nothing. No documentation, no architecture diagrams, no credentials. They find their own way in, just like an

Black Box, Grey Box, White Box: How to Choose the Right Pentest Methodology Read More »

man, reading, touchscreen, blog, digital, tablet, working, screen, touching, touch, samsung, stylus, pen, technology, device, coffee, coffee cup, cup

OSINT: What Hackers Might Already Know About Your Company  

Let’s start with the good news: most companies have an online footprint, and that’s totally normal. The less good news? Hackers love that footprint. The better news? With a bit of awareness, you can stay several steps ahead, without losing sleep or turning your office into a bunker.  Welcome to the pleasantly curious world of OSINT (Open-Source Intelligence): the art of collecting information that’s already

OSINT: What Hackers Might Already Know About Your Company   Read More »

A diverse team of business professionals collaborating in a modern meeting room.

Penetration Testing: The Strategic Investment That Pays Dividends in Confidence, Growth, and Trust 

What if security wasn’t just about preventing problems — but about enabling possibilities?  In today’s digital landscape, the most successful organizations have shifted their perspective on cybersecurity from reactive defense to proactive enablement. Within that mindset, penetration testing emerges not as a compliance checkbox, but as a strategic investment that strengthens foundations, accelerates innovation, and builds lasting

Penetration Testing: The Strategic Investment That Pays Dividends in Confidence, Growth, and Trust  Read More »

Ingang Refracted Partner Event

Refracted Security Partner Event: samenwerken aan structurele cyberweerbaarheid

Vorige week donderdag, 29 januari, mochten we met trots ons allereerste Refracted Security Partner Event organiseren. Geen klassiek salesmoment, maar een oprechte thank you aan de partners die reeds een hele tijd meebouwen aan ons verhaal. Sinds onze start in 2022 groeiden we uit tot een team van 16, waarvan 13 deep-technical cybersecurity experts met

Refracted Security Partner Event: samenwerken aan structurele cyberweerbaarheid Read More »

small office kmo

Hackers targetten jou niet, Je businessmodel heeft zichzelf targetbaar gemaakt 

“We zijn gehackt omdat we gekozen werden.” Dat is het dominante narratief na een incident. Een doelbewuste aanvaller, een gerichte poging, een slachtoffer dat uitgekozen werd.  Het klopt niet.  Hackers targetten jou niet. Hackers kiezen geen slachtoffers zoals een inbreker huizen kiest. Ze optimaliseren frictieloze extractie. Ze zoeken niet naar wie ze willen aanvallen, maar naar wie het makkelijkst betaalt.  Dat onderscheid klinkt subtiel. Het is fundamenteel.  Hackers volgen geen targets — ze volgen betalingszekerheid  Moderne cybercriminaliteit is een industrieel proces. Geen artistieke heist, geen persoonlijke vendetta, geen Hollywood-scenario. Het is optimalisatie van rendement per tijdseenheid.  Wat bepaalt of jij interessant bent? Vier variabelen:  1. Time-to-impact (hoe snel ontstaat schade?)  Hoe lang duurt het voordat jouw organisatie pijn voelt? Bedrijven met real-time afhankelijkheden — webshops, productie, dienstverlening — voelen druk binnen uren. Bedrijven met buffers en alternatieven kunnen dagen of weken wachten. De aanvaller kiest het eerste.  2. Cashflow-elasticiteit (hoe snel doet financiële pijn écht pijn?)  Een bedrijf met brede marges en reserves kan schokken opvangen. Een bedrijf dat draait op krappe cashflow en just-in-time levering niet. Hackers modelleren dit impliciet: ze zoeken organisaties waar geld vastzit in operaties, niet op de bank.  3. Alternatieven (kan het bedrijf omzeilen of wachten?)  Zijn er back-ups die snel te activeren zijn? Kunnen klanten tijdelijk anders bediend worden? Kunnen processen handmatig? Hoe minder alternatieven, hoe hoger de betalingsbereidheid.  4. Beslissingschaos (hoe rommelig is crisismanagement?)  Organisaties die snel, helder en gedecentraliseerd beslissen zijn minder kwetsbaar. Organisaties waar niemand weet wie beslist, waar paniek escaleert en waar ad-hoc geïmproviseerd wordt, zijn goudmijnen voor aanvallers.

Hackers targetten jou niet, Je businessmodel heeft zichzelf targetbaar gemaakt  Read More »

Eyeglasses reflecting computer code on a monitor, ideal for technology and programming themes.

Compliance and Penetration Testing: A Comprehensive Guide 

1. Penetration Testing: The Cornerstone of Modern Security  Penetration testing (pen testing) is no longer optional—it is a mandatory and foundational requirement in virtually every major international standard and regulatory framework.  For modern organizations, compliance-focused penetration testing is recognized as a critical component of a proactive cybersecurity strategy to validate whether existing defenses can withstand

Compliance and Penetration Testing: A Comprehensive Guide  Read More »

Annaconquer event Annacon x Refracted

COMMAND & ANNACONQUER: Recap

We Came, We Hacked, We Conquered What happens when you mix curious minds, laptops, and Hack The Box challenges? You get one epic night of hacking, learning, and community vibes. On August 21, ANNACON launched its very first COMMAND & ANNACONQUER event — and we at Refracted Security were happy to help host the event,

COMMAND & ANNACONQUER: Recap Read More »

Scroll to Top