Our methodology
A transparent, standards-aligned process that delivers consistent, high-quality results — and protects your data along the way.
Standards we follow
Our engagements align with recognised industry frameworks so results are consistent, repeatable and accepted by auditors:
- OWASP WSTG
- OWASP ASVS
- OWASP MASVS / MASTG
- OWASP API Security Top 10
- OWASP Top 10 for LLM Applications
- PTES
- NIST SP 800-115
- NIST SP 800-61
- MITRE ATT&CK
- CVSS
- CIS Benchmarks
Penetration testing lifecycle
- ScopingWe confirm assets, objectives, environments, user roles, test windows and compliance requirements, and estimate effort in tester-days.
- Authorisation & rules of engagementWritten authorisation, exclusions, source IPs, emergency contacts and data-handling rules are agreed before testing begins.
- ReconnaissanceWe map the attack surface: hosts, endpoints, technologies, roles and data flows.
- Manual testingExperienced testers attack each area by hand, using tooling to extend coverage. Critical issues are reported immediately.
- Exploitation & chainingVulnerabilities are safely exploited and combined to demonstrate realistic business impact, within agreed limits.
- ReportingExecutive summary, methodology, scope, risk-rated findings with evidence, and specific remediation guidance.
- Debrief & retestA walkthrough with your engineers, followed by verification of fixes and an attestation letter.
How we rate risk
We start with CVSS to describe technical severity, then adjust for your context — exposure, data sensitivity, compensating controls and ease of exploitation — so priorities reflect real business risk.
| Rating | Meaning | Suggested fix time |
|---|---|---|
| Critical | Direct, easily exploitable path to significant data or system compromise | Immediately / within 7–15 days |
| High | Serious impact, with some preconditions | Within 30 days |
| Medium | Limited impact or harder to exploit | Within 90 days |
| Low | Minor weakness or defence-in-depth improvement | Next planned release |
| Informational | Observations and hardening advice | As appropriate |
Managed services operating model
For SOC, NOC, vulnerability and patch management services, we follow a structured onboarding → tuning → operate → review cycle with documented runbooks, defined severities, escalation paths and monthly service reviews.
Data handling & confidentiality
- All engagements covered by NDA and written authorisation
- Client data and findings stored encrypted with least-privilege access
- Reports shared through secure channels only
- Test accounts and access revoked at engagement close
- Engagement data securely deleted per agreed retention periods
Ready to find your risks before attackers do?
Tell us what you need tested or monitored. A senior consultant replies within one business day with a scoped, fixed-price proposal.
- Fixed-price proposal
- Reply within 1 business day
- NDA on request