The S Unit B.v.
The S-Unit B.V. is a Dutch offensive cybersecurity firm that delivers custom penetration testing, red teaming, and security consultancy to enterprises across the Netherlands, with proprietary specialization in the Mendix low-code platform and a co-developed SAST module.
- Company typePrivate
- Founded2015
- HeadquartersUtrecht, Netherlands
- Headcount11–50
- GTM typeB2B
- OfferingServices
What The S Unit B.v. does
The S-Unit B.V. is a Dutch offensive cybersecurity services firm headquartered in Utrecht, founded in 2011 as a business unit by Dirk van Veen and Barry van Kampen, incorporated as an independent entity in 2015, and operating as part of the DSE-groep since 2018. The company employs approximately 25–27 security professionals who deliver custom penetration testing, red teaming, and social engineering services, alongside a consultancy practice covering CISO advisory, cyber crisis simulation, and phishing campaigns. Its core proposition is high-trust, manual offensive security work — explicitly positioned against automated scanners — with deep specialization in the Mendix low-code platform, codified in the proprietary "The S-Unit Top 10 Mendix Vulnerabilities" framework.
The technology stack is anchored by tradecraft rather than platforms. The S-Unit develops proprietary offensive tools (Kraken) and has co-developed a Mendix-specific SAST module with Omnext that integrates its Top 10 framework into CI/CD pipelines, converting some of its intellectual property into recurring software-like revenue. The S-University is the training arm, offering both public and in-house courses priced from €275 to €2,475 per participant, covering ethical hacking, Mendix security, Azure/M365 security, red teaming, OSINT, and security awareness. The S-Unit uses Fortra tooling (Core Impact, Cobalt Strike, Outflank) for red team operations and is a member of Hack in the Box and the Dutch Platform for Information Security (PvIB).
The business model is professional services anchored on long-term enterprise relationships. The firm serves a primarily Dutch enterprise base across financial services, healthcare, government, software vendors, ICT and media, energy, and transportation, with named clients including Mendix (as a flagship monthly-recurring customer), NS, Rijkswaterstaat, Port of Rotterdam, Maasstad Ziekenhuis, Schuberg Philis, Mediahuis, ICTRecht, and Frank Energie. Go-to-market combines enterprise field sales with community-led demand generation: annual CTF events, pro bono testing for non-profits, conference participation, and content marketing. The S-Unit executes more than 200 penetration tests per year and reports an 87% customer satisfaction score.
The S Unit B.v. firmographics
Firmographics- Name
- The S Unit B.v.
- Legal name
- The S-Unit B.V.
- Website
- https://the-s-unit.nl
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- The S-Unit B.V. is a Dutch offensive cybersecurity firm that delivers custom penetration testing, red teaming, and security consultancy to enterprises across the Netherlands, with proprietary specialization in the Mendix low-code platform and a co-developed SAST module.
- Ownership category
- akta.pro rank
The S Unit B.v. industry classification
Industry- Product category
- Offensive Cybersecurity Services
- NAICS
- Other Computer Related Services (541519), Computer Training (61142), Computer Training (611420)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKADAE)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH), Phishing, Social Engineering & Business Email Compromise (BEC) Training (EDABAGAB)
Keywords
Where The S Unit B.v. is headquartered
LocationHeadquarters
- HQ city
- Utrecht
- HQ country
- Netherlands
- HQ region
- Europe
Offices1 record
Markets served
The S Unit B.v. business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Penetration Testing Services: Recurring and project-based penetration testing services including web applications, mobile apps, Mendix applications, infrastructure, cloud environments (Azure, M365), and red teaming operations. Services delivered by certified ethical hackers with monthly engagements for key clients like Mendix.
- Security Consultancy: Strategic and tactical security advisory services including CISO guidance, security roadmap development, crisis simulation, and policy development. Delivered through Security Advisors and technical consultants.
- Training Services: Instructor-led training programs on security topics including ethical hacking, Mendix security, Azure/M365 security, red teaming, OSINT, and security awareness. Offered at various price points from 275 to 2250 EUR per participant with public and in-house delivery options.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Pay-as-you-go | NIS2 Boardroom Training - Executive compliance training |
| One time/ perpetual license | Pay-as-you-go | Mendix Security Fundamentals - Entry-level Mendix security training |
| One time/ perpetual license | Pay-as-you-go | Mendix Security Advanced - Intermediate Mendix security training |
| One time/ perpetual license | Pay-as-you-go | Mendix Security Expert - Expert-level Mendix security certification |
| One time/ perpetual license | Pay-as-you-go | Security Awareness - Basic employee awareness training |
| One time/ perpetual license | Pay-as-you-go | Security Awareness Hackers - Hacker perspective awareness training |
| One time/ perpetual license | Pay-as-you-go | Cybercrisis Simulation - Crisis response tabletop training |
| One time/ perpetual license | Pay-as-you-go | OSINT Cyber Hunt - Open source intelligence workshop |
| One time/ perpetual license | Pay-as-you-go | OSINT Presentation - Awareness presentation on digital footprint |
| One time/ perpetual license | Pay-as-you-go | Ethical Hacking Web Applications - OWASP Top 10 training |
| One time/ perpetual license | Pay-as-you-go | Red Teaming Training Under The Radar - Advanced red team operations |
| One time/ perpetual license | Pay-as-you-go | Security in Microsoft 365 and Azure - Cloud security training |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels6 records
The S Unit B.v. product offering
Product offeringCore offering
The S-Unit delivers offensive cybersecurity services — controlled penetration testing, full-scope red teaming, and security consultancy — to expose unknown vulnerabilities unique to each client's environment across web, mobile, Mendix low-code, infrastructure, cloud (Azure, M365), and operational technology. Training is delivered through The S-University platform, offering courses on ethical hacking, Mendix security, OSINT, cloud security, red teaming, and security awareness for both developers and general staff.
Product overview
The S-Unit is an offensive cybersecurity firm offering a portfolio of penetration testing, red teaming, and consultancy services organized around a core of ethical hacking. The offering is structured as a platform-plus-specialization model: its primary services are Pentesting and Red Teaming, which are complemented by specialized Mendix security testing, a full Consultancy suite (including cyber crisis simulation, social engineering, and phishing campaigns), and The S-University training arm. A key differentiator is The S-Unit Top 10 Mendix Vulnerabilities framework, a proprietary vulnerability classification system for Mendix applications that underpins both testing services and training, and the co-developed Omnext SAST integration for CI/CD pipelines. The company also provides NIS2 advisory and maintains community engagement through CTF events.
Differentiator
Problem solved
Functional benefit
Products and services
- Pentesting Controlled penetration testing services that identify and exploit unknown vulnerabilities unique to an organization's environment, covering web applications, mobile applications, Mendix low-code platforms, and complex environments including data centers, offices, operational technology, and cloud infrastructure (Azure, M365). Delivered by certified ethical hackers to enterprise clients with recurring and project-based engagement models.
- Red Teaming Full-scope offensive security operations that simulate realistic multi-layered attacks combining physical intrusion, social engineering, and technical intrusion vectors to test an organization's detection and response capabilities. Targeted at mission-critical organizations across retail, finance, and healthcare.
- Mendix Security Services Specialized penetration testing, security training, and vulnerability research focused on the Mendix low-code platform, including Mendix-specific CTF events and The S-Unit Top 10 Mendix Vulnerabilities framework. Includes monthly penetration testing retainer for Mendix as their security partner.
- Consultancy Strategic and tactical security consultancy encompassing guidance and advice, cyber crisis simulation, phishing campaigns, social engineering assessments, and mystery guest evaluations. Delivered by Security Advisors and senior consultants to enterprise and government clients.
- The S-University Training Programs Educational platform offering cybersecurity training programs including NIS2 Boardroom Training (€2,475/session), Mendix Security Fundamentals (€995/person), Mendix Security Advanced (€1,200/person), Mendix Security Expert (€1,400/person, leads to official Mendix certification), Security Awareness (€275/person), Security Awareness Hackers (€750), Cybercrisis Simulation (€375/session), OSINT Cyber Hunt workshop (€495/person), OSINT Presentation (€995), Ethical Hacking Web Applications (€1,475, 2 days), Red Teaming Under The Radar (€2,250/person, 3 days, includes Cobalt Strike license), and Security in Microsoft 365 and Azure (€1,475, 2 days). Delivered as public sessions at The S-Unit Utrecht office and in-house at client locations, in Dutch and optionally English.
- NIS2 Advisory Advisory services helping organizations understand and prepare for NIS2 Directive compliance requirements, complemented by NIS2 Boardroom executive training.
Quantifiable outcome
- 87% customer satisfaction score
- +2 more outcomes
Companies that use The S Unit B.v.
Customer profileNamed customers10 records
Segments8 records
Ideal customer profiles5 records
The S Unit B.v. technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
The S Unit B.v. partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core, flagship and minor.
- OmnextcoreJoint development of Mendix-specific SAST (Static Application Security Testing) module. The solution integrates The S-Unit Top 10 vulnerabilities into CI/CD pipelines for automatic scanning throughout the development lifecycle. Combined Omnext's software analysis platform with The S-Unit's offensive security expertise.
- Eye SecuritycorePartnership to bridge the gap between detection and offensive security. Eye Security helps SMB organizations proactively identify cyber risks and strengthen their operational resilience. The partnership combines offensive security testing from The S-Unit with detection capabilities from Eye Security.
- FortracoreOffensive security partnership in Benelux. Fortra develops advanced technologies including Core Impact, Cobalt Strike, and Outflank Security Tooling (OST) for realistic attack simulation. The S-Unit uses Fortra tools in red teaming exercises and training programs.
- MendixflagshipMendix is a leading low-code platform and The S-Unit serves as their security partner, performing monthly penetration testing and organizing annual CTF events for the developer community. The S-Unit has developed The S-Unit Top 10 Mendix Vulnerabilities based on this partnership.
- DSE-groepcoreThe S-Unit has been part of the DSE-groep (DSE Group) since 2018, providing corporate backing and potential synergies with other group companies.
- Platform voor Informatiebeveiliging (PvIB)minorActive member of the Dutch Platform for Information Security. Participates by sharing knowledge and ideas with the security community.
- Hack in the BoxminorOrganized hack competitions and participated in international conferences. Dirk van Veen organized hack competitions for Hack in the Box from 2012-2019.
Scale indicators4 records
Recent moves8 records
Expansion highlights10 records
The S Unit B.v. competitors and assessment
Company assessmentBroad incumbents
- NCC Group: NCC Group is a global cybersecurity specialist with a substantial Dutch presence (via Fox-IT) covering pen testing, red teaming, escrow, and managed detection. Comparable in core offensive-security services but at much larger scale and broader geographic reach than The S-Unit.
- Deloitte Netherlands Cyber Risk: Deloitte Netherlands runs a Cyber Risk practice spanning offensive security testing, red teaming, NIS2 advisory, and managed security for major Dutch and EU enterprises. Comparable on enterprise customer base and offensive-security service line, though embedded within a global Big 4 advisory franchise.
- PwC Netherlands Cyber Security: PwC Netherlands provides cybersecurity consulting, penetration testing, and compliance advisory (including NIS2 readiness) to large Dutch enterprises and government. Comparable on regulated-vertical clients and broad security service portfolio, though at substantially larger scale.
- KPMG Netherlands Cyber Security: KPMG Netherlands operates a large cybersecurity advisory practice covering pen testing, red teaming, NIS2 advisory, and managed security. Comparable to The S-Unit on enterprise/government clients and pen testing/red teaming services, but operating as part of a global Big 4 portfolio.
Direct peers
- Secura: Secura (now part of DNV) is a Dutch cybersecurity firm specializing in pen testing, red teaming, and security advisory across enterprise and OT environments. Directly comparable to The S-Unit on geography (Netherlands), service portfolio, and target customer profile (regulated enterprises and government).
- PenTest People: PenTest People is a UK-based penetration testing specialist delivering CREST-accredited testing, red team, and training services to enterprise and public-sector clients. Comparable to The S-Unit on boutique scale, service portfolio, and SMB/mid-market enterprise customer profile.
- Bishop Fox: Bishop Fox is a US-based boutique offensive-security firm specializing in penetration testing, red teaming, and security research. Closely analogous to The S-Unit in operating model (boutique, expertise-led, custom over automated) and service mix, though serving US enterprise clients.
- Fox-IT: Fox-IT is a Delft-based Dutch cybersecurity firm (acquired by NCC Group) offering penetration testing, managed security services, and threat intelligence. Closest comparable in terms of Dutch origin, enterprise/government client base, and offensive-security heritage, though now scaled under NCC Group ownership.
Emerging players
- Outflank: Outflank is a Dutch offensive-security firm offering red team operations, attack-surface management, and Outflank Security Tooling (OST). Comparable niche offensive-security focus and Dutch origin; also a Fortra partner alongside The S-Unit. Smaller and more tooling-oriented than The S-Unit's full-service model.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights7 records
Customer concentration
The S Unit B.v. social profiles
Digital presenceThe S Unit B.v. financial estimates
Financial estimateRevenue estimate
Valuation estimate
The S Unit B.v. leadership team
Management profileNumber of profiles
Profiles6 records
The S Unit B.v. funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
The S Unit B.v. M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about The S Unit B.v.
What does The S Unit B.v. do?
The S-Unit delivers offensive cybersecurity services — controlled penetration testing, full-scope red teaming, and security consultancy — to expose unknown vulnerabilities unique to each client's environment across web, mobile, Mendix low-code, infrastructure, cloud (Azure, M365), and operational technology. Training is delivered through The S-University platform, offering courses on ethical hacking, Mendix security, OSINT, cloud security, red teaming, and security awareness for both developers and general staff.
Is The S Unit B.v. a public or private company?
The S Unit B.v. is a private company. It is classified as corporate owned and is currently operating.
When was The S Unit B.v. founded?
The S Unit B.v. was founded in 2015. It employs 11 to 50 people.
Where is The S Unit B.v. based?
The S Unit B.v. is headquartered in Utrecht, Netherlands, in the Europe region.
How does The S Unit B.v. make money?
Three revenue lines are on record. Penetration Testing Services are the primary driver. The others are security Consultancy and training Services.
Who are The S Unit B.v.'s main competitors?
Broad incumbents on record are NCC Group, Deloitte Netherlands Cyber Risk, PwC Netherlands Cyber Security and KPMG Netherlands Cyber Security. Direct peers are Secura, PenTest People, Bishop Fox and Fox-IT. Outflank is listed as an emerging player.
Does The S Unit B.v. have an API?
No public API is recorded for The S Unit B.v..
What industry is The S Unit B.v. in?
The S Unit B.v.'s product category is Offensive Cybersecurity Services. Its primary akta.pro industry code is BPAKADAE, Penetration Testing & Red Teaming, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 541519 and its SIC code is 7370.