MIAUW: A Structured Approach for Trustworthy Information Security Research
In a world in which cybersecurity risks are becoming increasingly complex and legislation such as the NIS2 directive and the Cyber Resilience Act forces organizations to be demonstrably “in control”, carrying out a penetration test (pen test) is no longer sufficient. The question is not only whether a test has been carried out, but also how and with what certainty the results are reliable and reproducible.
That is why the Methodology for Information Security Research with Audit Value (MIAUW) has been developed. This is a structured framework for penetration testing, which allows companies and governments to demonstrate with certainty that their systems have been tested in an auditable, repeatable and transparent manner. This is now part of the LibreKAT Foundation.
Why is MIAUW special?
Many traditional penetration tests lack a standardized approach, leading to varying results and uncertainty about the completeness of the investigation. MIAUW is designed to change this. The methodology ensures that:
- Every step of the test is imitable and irrefutable.
- An official report can be drawn up by an auditor, so that external parties can confirm the validity of the research.
- The scope, context and research depth are clearly documented.
- Findings are graded objectively, so that priorities become clear.
- All tests and findings performed are repeatable, simplifying audits and compliance checks.
MIAUW is not just a standard for pen testing; it offers a holistic method that creates both technological and legal certainty.
Open source as a basis for transparency and reliability
MIAUW is an open-source methodology, which means that anyone can view, use and improve the principles. This not only ensures broad support and transparency, but also prevents dependence on commercial parties that hide tests and results in a ‘black box’.
Open source is particularly effective in an ecosystem. At MIAUW we have forged a Coalition of Willing of parties who liked the approach. That led to great partnerships and, above all, a lot of collaboration. After all, you don’t do something like this alone. Many people also make MIAUW a great community effort. For example, a lot of work has also been done: Jeroen Diel, Mischa van Geelen, Maaike Hielkema, Hans van de Looy and Victor Pous.
The open nature of MIAUW allows companies and governments to:
- Check the quality of the research and reporting yourself.
- Collaborate with independent experts and auditors for validation.
- Easier to meet compliance requirements, because the methodology is aligned with international standards.
MIAUW joins valuable, existing initiatives such as the CCV pentest quality mark, which offers a standardized and reliable way to test and assess information security investigations.
MIAUW core technical principles
The methodology is based on a number of essential principles that ensure that pen tests are not only technically thorough, but also legally and audit-proof.
Imitable and provable research
MIAUW ensures that all tests performed are documented and verifiable. This means that:
- Each step of the test is supported by evidence (such as screenshots and logs).
- An auditor can assess the investigation without having to completely re-execute it.
- It is clear who tested what, how and why.
This creates an audit trail with which organizations can demonstrate to regulators that a test has been carried out correctly and completely.
Reproducibility and comparison over time
With MIAUW, security teams can compare the status of a system at different times. This is crucial, because vulnerabilities are not always discovered immediately, but are only activated or exploited later.
- The methodology records which tests have been carried out and what the results were.
- This allows an organization to easily assess whether the security posture is improving or deteriorating.
- This supports the principle of “continuous security monitoring” as required under NIS2.
Policy-driven alerts with business rules
Not all vulnerabilities are equally important, and not every technical problem poses a business risk. MIAUW makes it possible to apply business rules to pentest results, so that notifications and reports are filtered based on what is relevant to the organization.
- Organizations can determine when and on what alerts are generated.
- This prevents ’noise’ from low-risk reports and focuses on what really matters.
- Risks are placed in the right business context, so that management and security teams can make better-informed decisions.
MIAUW in practice: a better way of pentesting
MIAUW is already used in sectors where security and compliance are essential, such as government, healthcare and financial services. Through a combination of technical in-depth testing and audit mechanisms, MIAUW ensures that:
✅ Information security research provides demonstrable certainty, instead of a subjective snapshot. ✅ Organizations can better fulfill their compliance and security responsibilities through reproducible results and clear audit trails. ✅ Pentest results are not dependent on the interpretation of one tester, but are reported and validated in a standardized manner.
Otis as the mascot of MIAUW
Since the abbreviation MIAUW is reminiscent of cats, it was only logical to have a cat as a mascot. That is what Otis, Brenno de Winter’s beautiful cat, has become. Of course in a position where he is miauwing. As an ocikat, Otis has an inquisitive, friendly and social character. By the way, he is a bit dominant and is not afraid to let it be known that he wants or does not approve of something.

Why MIAUW is a game-changer in security
The development of MIAUW is a direct response to the growing demand for transparent, repeatable and auditable pen testing. By following this methodology, organizations can not only operate more securely, but also demonstrate to regulators, customers and internal stakeholders that their security policy meets the highest standards.