Calder Holding Further Strengthens Information Security with an Independent Penetration Test by OneXillium

Customer Case Study
Customer Case Studies
OneXillium - logo-calder-holding-01

From ISO 27001 to Greater Assurance
Calder Holding has been ISO 27001-certified for more than three years. This certification forms the foundation for information security within the organization. Building on this solid foundation, the company sought to gain additional, independent insight into the actual resilience of its IT environment.

Given the sensitivity of the information and the role of people in the processes, Calder wanted a concrete understanding of its vulnerabilities and risks. That is why Calder decided to engage an external, independent party to conduct a comprehensive penetration test—not as a corrective measure, but as an in-depth audit to verify assumptions and prevent blind spots.

Our Solutions

OneXillium - Capable Utrecht
About Calder Holding

Calder Holding is a socially driven organization active in the fields of education, healthcare, and employment. Guided by the motto “from inactive to active,” Calder supports people in their personal development and encourages them to make the most of their talents and potential. By continuously adapting to social developments, new legislation, and technological innovations, Calder remains a healthy and forward-looking organization.

“To gain a clear understanding of how well our security infrastructure can withstand hacker attacks, we needed an outside party

Luuk Sommers
Senior .NET Developer at Calder Holding
Why Choose OneXillium

Calder wasn't familiar with OneXillium at first. The search began simply with a Google search, asking, " Who can help us with a penetration test?"
Ultimately, it was a combination of proximity, attitude, and expertise that sealed the deal:

  • OneXillium is literally just around the corner, in Arnhem, near Calder.
  • Our first interaction felt comfortable right away. Down-to-earth, honest, and without any frills.
  • The focus was not on big names or impressive projects, but on quality and genuine improvements in security.
  • The quote was clear and competitive.
The tests conducted

To establish a complete baseline, several tests were conducted, including:

  • Black-box penetration test on the external infrastructure
  • Greybox penetration testing on the client portals
  • Assume Breach Test on the Internal Infrastructure
  • Workplace study focused on the new, standardized workstations

This combination gave Calder insight into both external threats and internal risks, including human behavior and legal structures.

Insights that inspire action

The findings partly confirmed existing assumptions, but also brought new areas of concern to light. The most important insights included the following:

  • Handling of Information
  • rights and authorizations
  • employee awareness

As a result, not only the IT department but also the executive board and management became even more involved in information security.

From Assessment to Structural Improvement

For Calder, the penetration test was not an end in itself, but a logical next step within the ISO 27001 cycle of continuous improvement.

  • All findings have been recorded in the nonconformity log
  • Policies have been revised and processes have been streamlined
  • Applications are being improved to enable the sharing of information in a more secure and controlled manner

In addition, Calder has opted for a new security awareness module from OneXillium. The previous training did not sufficiently reflect real-world situations. The new approach uses concrete statistics and measurable results, which are also shared with employees.

Why Calder Recommends OneXillium

What Calder particularly appreciates is not only the pleasant collaboration, but above all the high quality and thoroughness of the penetration tests conducted.

  • Clear and prompt communication throughout the entire penetration testing process, with direct lines of communication between the Red Team and Calder’s staff.
  • Critical findings were shared immediately, even while testing was still underway. This allowed Calder to take immediate action, rather than waiting for the final report.
  • Thorough and professional execution of the tests, which not only uncovered technical vulnerabilities but also provided insight into their interrelationships and underlying causes.
  • A quick and clear report, with concrete, realistic, and well-reasoned recommendations that could be implemented immediately within the organization.
OneXillium - logo-calder-holding-01

“Other companies mainly promoted themselves based on their results. OneXillium kept both feet on the ground and really focused on how we could improve our security.”

Luuk Sommers
Senior .NET Developer at Calder Holding
Conclusion

Through OneXillium’s independent penetration test, Calder Holding has strengthened its existing ISO 27001 foundation with concrete technical and organizational insights. The result is an organization that continues to work on information security in a more informed, well-founded, and forward-looking manner.

Customer Case Studies
OneXillium - barentz-logo
Customer Case Studies
OneXillium - Logo_BNP Paribas
Customer Case Studies
OneXillium - logo-carbogen-amcis
Customer Case Studies
Customer Case Studies
OneXillium - logo-p1-qpark
Customer Case Studies
OneXillium - Logo_van-lanschot
Customer Case Studies
OneXillium - Gelder Logo
Customer Case Studies
OneXillium - Scratch Logo
Customer Case Studies
Customer Case Studies
OneXillium - heleon-group-logo
Customer Case Studies
OneXillium - Animal Welfare Logo

Request a no-obligation consultation!

Are you inspired?

Eigen Haard isn’t the only housing authority using our EIM solution, Xtendis. Learn all about it on our housing authority page, or contact us if you’d like to gain even more insight and control over your overall information management.