GitLab host manages GitLab for businesses of varying sizes: from web agencies in Groningen to international names, such as Porsche. Customers use their GitLab environment to build software — for many of them, often the heart of the organization. Anyone who entrusts their source code, pipelines, and deployments to a hosting provider wants assurance that the provider handles security properly. That responsibility begins with trust.
Why cybersecurity became increasingly urgent
The need for stable security has only grown in recent years at Gitlabhost. “Due to the rise of AI, there are more ways to attack and more ways to gain access, and that development went at a rapid pace,” says Leon Koens, DevOps Engineer at Gitlabhost. In addition, Gitlabhost is receiving increasingly frequent questions from customers about DORA (the Digital Operational Resilience Act). This European regulation requires financial institutions to manage their ICT risks and strengthen their digital resilience. Those requirements cascade down to their IT suppliers, and therefore to Gitlabhost.
Knowing where you are vulnerable
For technical support, Gitlabhost turned to Warpnet. The request was clear: identify potential vulnerabilities in the systems. Warpnet performed pentests on various systems and on the database.
Leon on the collaboration: “Communication with the pentesters was very good and easy. The quality of the reporting was very high and comprehensive, including examples and screenshots. That ensured we could get to work right away.”
Nikhil, pentester at Warpnet, adds: “Contact with Leon was very accessible, which ensures that we can carry out the pentest carefully.”
An ISMS that is continuously maintained by Nestor Security
Gitlabhost already had ISO 27001 certification and security was already high on the agenda. What was needed: support in maintaining and monitoring the ISMS, the management system with which information security is structurally managed and improved. For this, Gitlabhost engaged our partner Nestor Security in.
Nestor Security is working within the ISMS platform Base27 on the context analysis, a systematic analysis of the internal and external factors that influence an organization's information security. In addition, Nestor Security identifies relevant laws and regulations, and it is being examined whether Gitlabhost must also comply with regulations such as NIS2 and DORA.
A partnership close to home
When choosing a partner, a local presence was an important condition for Gitlabhost. Leon says: “We wanted a party from Groningen so that we can easily meet each other face-to-face; that works better for us than online. In addition, quality and experience with Base27 were a prerequisite.”
Maintaining an ISMS takes time. Time that is not always available alongside daily operations. By outsourcing this, above all one thing disappeared for Gitlabhost: the worry.
“Gitlabhost is dealing with rapid technological changes. Almost daily there are developments or incidents that we have to take into account. It is a lot of work to keep track of that ourselves,” says Kirsten, Security Consultant at Nestor Security.
Combination of ISMS and technology
Through the combination of a continuously maintained ISMS and technical deep-dives via pentests, Gitlabhost maintains a grip on the security of the environments that customers rely on — even as laws and regulations, such as NIS2 and DORA, are tightened further.