Deliverables
Deliverables
Deliverables are written for two audiences at once: the people who have to make a risk decision, and the engineers who have to implement the fix.
Report structure
A full engagement report contains the following sections.
- 01
Executive summary
Risk summarised in business language, with an overview of finding counts and severities.
- 02
Scope and authorisation
What was in scope, what was excluded, the testing window, and the authorisation record relied upon.
- 03
Methodology applied
The approach and the referenced standards as they were applied to this specific engagement.
- 04
Detailed findings
Each with a description, affected location, reproduction steps, evidence, severity rating and remediation guidance.
- 05
Impact analysis
What each finding means for your business in its real operating context.
- 06
Prioritised remediation plan
Remediation work ordered by impact and by implementation effort.
- 07
Testing limitations
An explicit record of what could not be tested, or could not be tested fully, and why.
- 08
Appendices
Tooling used, significant activity logs, and supporting reference material.
Delivery formats
- Full report as PDF
- Findings summary suitable for import into your issue tracker
- Review session with your team
- Closure report following retesting
Handling of sensitive material
- Delivered over an encrypted channel agreed in advance
- Access restricted to named recipients on both sides
- Engagement data destroyed on the schedule set in the contract
- Critical findings reported immediately during testing, not held back for the report
Would a redacted sample report help? Contact us and we will provide one. We never publish any client’s report.
Contact
Start with a scoping conversation
Tell us roughly what you need tested and we will come back with a proposed scope, duration and testing approach.
We test only with written authorisation and only within the agreed scope.