Calder Holding Further Strengthens Information Security with an Independent Penetration Test by OneXillium

From ISO 27001 to Greater Assurance
Calder Holding has been ISO 27001-certified for more than three years. This certification forms the foundation for information security within the organization. Building on this solid foundation, the company sought to gain additional, independent insight into the actual resilience of its IT environment.
Given the sensitivity of the information and the role of people in the processes, Calder wanted a concrete understanding of its vulnerabilities and risks. That is why Calder decided to engage an external, independent party to conduct a comprehensive penetration test—not as a corrective measure, but as an in-depth audit to verify assumptions and prevent blind spots.
Our Solutions
Calder Holding is a socially driven organization active in the fields of education, healthcare, and employment. Guided by the motto “from inactive to active,” Calder supports people in their personal development and encourages them to make the most of their talents and potential. By continuously adapting to social developments, new legislation, and technological innovations, Calder remains a healthy and forward-looking organization.
Calder wasn't familiar with OneXillium at first. The search began simply with a Google search, asking, " Who can help us with a penetration test?"
Ultimately, it was a combination of proximity, attitude, and expertise that sealed the deal:
- OneXillium is literally just around the corner, in Arnhem, near Calder.
- Our first interaction felt comfortable right away. Down-to-earth, honest, and without any frills.
- The focus was not on big names or impressive projects, but on quality and genuine improvements in security.
- The quote was clear and competitive.
To establish a complete baseline, several tests were conducted, including:
- Black-box penetration test on the external infrastructure
- Greybox penetration testing on the client portals
- Assume Breach Test on the Internal Infrastructure
- Workplace study focused on the new, standardized workstations
This combination gave Calder insight into both external threats and internal risks, including human behavior and legal structures.
The findings partly confirmed existing assumptions, but also brought new areas of concern to light. The most important insights included the following:
- Handling of Information
- rights and authorizations
- employee awareness
As a result, not only the IT department but also the executive board and management became even more involved in information security.
For Calder, the penetration test was not an end in itself, but a logical next step within the ISO 27001 cycle of continuous improvement.
- All findings have been recorded in the nonconformity log
- Policies have been revised and processes have been streamlined
- Applications are being improved to enable the sharing of information in a more secure and controlled manner
In addition, Calder has opted for a new security awareness module from OneXillium. The previous training did not sufficiently reflect real-world situations. The new approach uses concrete statistics and measurable results, which are also shared with employees.
What Calder particularly appreciates is not only the pleasant collaboration, but above all the high quality and thoroughness of the penetration tests conducted.
- Clear and prompt communication throughout the entire penetration testing process, with direct lines of communication between the Red Team and Calder’s staff.
- Critical findings were shared immediately, even while testing was still underway. This allowed Calder to take immediate action, rather than waiting for the final report.
- Thorough and professional execution of the tests, which not only uncovered technical vulnerabilities but also provided insight into their interrelationships and underlying causes.
- A quick and clear report, with concrete, realistic, and well-reasoned recommendations that could be implemented immediately within the organization.
Through OneXillium’s independent penetration test, Calder Holding has strengthened its existing ISO 27001 foundation with concrete technical and organizational insights. The result is an organization that continues to work on information security in a more informed, well-founded, and forward-looking manner.
Request a no-obligation consultation!
Eigen Haard isn’t the only housing authority using our EIM solution, Xtendis. Learn all about it on our housing authority page, or contact us if you’d like to gain even more insight and control over your overall information management.




















