24/7 SOC monitoring & incident responsesales@bugfoe.com
BestPentestingby BugFoe
How we work

Our methodology

A transparent, standards-aligned process that delivers consistent, high-quality results — and protects your data along the way.

Standards we follow

Our engagements align with recognised industry frameworks so results are consistent, repeatable and accepted by auditors:

  • OWASP WSTG
  • OWASP ASVS
  • OWASP MASVS / MASTG
  • OWASP API Security Top 10
  • OWASP Top 10 for LLM Applications
  • PTES
  • NIST SP 800-115
  • NIST SP 800-61
  • MITRE ATT&CK
  • CVSS
  • CIS Benchmarks

Penetration testing lifecycle

  1. ScopingWe confirm assets, objectives, environments, user roles, test windows and compliance requirements, and estimate effort in tester-days.
  2. Authorisation & rules of engagementWritten authorisation, exclusions, source IPs, emergency contacts and data-handling rules are agreed before testing begins.
  3. ReconnaissanceWe map the attack surface: hosts, endpoints, technologies, roles and data flows.
  4. Manual testingExperienced testers attack each area by hand, using tooling to extend coverage. Critical issues are reported immediately.
  5. Exploitation & chainingVulnerabilities are safely exploited and combined to demonstrate realistic business impact, within agreed limits.
  6. ReportingExecutive summary, methodology, scope, risk-rated findings with evidence, and specific remediation guidance.
  7. Debrief & retestA walkthrough with your engineers, followed by verification of fixes and an attestation letter.

How we rate risk

We start with CVSS to describe technical severity, then adjust for your context — exposure, data sensitivity, compensating controls and ease of exploitation — so priorities reflect real business risk.

RatingMeaningSuggested fix time
CriticalDirect, easily exploitable path to significant data or system compromiseImmediately / within 7–15 days
HighSerious impact, with some preconditionsWithin 30 days
MediumLimited impact or harder to exploitWithin 90 days
LowMinor weakness or defence-in-depth improvementNext planned release
InformationalObservations and hardening adviceAs appropriate

Managed services operating model

For SOC, NOC, vulnerability and patch management services, we follow a structured onboarding → tuning → operate → review cycle with documented runbooks, defined severities, escalation paths and monthly service reviews.

Data handling & confidentiality

  • All engagements covered by NDA and written authorisation
  • Client data and findings stored encrypted with least-privilege access
  • Reports shared through secure channels only
  • Test accounts and access revoked at engagement close
  • Engagement data securely deleted per agreed retention periods

Ready to find your risks before attackers do?

Tell us what you need tested or monitored. A senior consultant replies within one business day with a scoped, fixed-price proposal.

  • Fixed-price proposal
  • Reply within 1 business day
  • NDA on request