Methodology

Methodology

We work through a defined sequence and document each stage, so results are traceable and repeatable — by our own team and by an external reviewer.

Engagement phases

  1. Scoping and authorisation

    Identify target systems, environments, testing window and contacts, then obtain written authorisation before any testing begins.

  2. Rules of engagement

    Agree what is and is not permitted — including availability-affecting tests, emergency contact channels, and the conditions under which we stop immediately.

  3. Threat modelling

    Understand the architecture, trust boundaries and valuable assets, so testing time is spent where it produces the most useful result.

  4. Manual and tool-assisted testing

    Tools map the attack surface broadly; manual testing goes deep where understanding the application’s context is what actually finds the flaw.

  5. Exploit validation in the authorised environment

    Demonstrate that a finding is genuinely exploitable within the authorised environment, separating real risk from theoretical risk.

  6. Impact analysis

    Assess business impact in your context rather than relying on a base severity score alone.

  7. Evidence-backed reporting

    Every finding carries reproduction steps, evidence, a CVSS severity rating and specific remediation guidance.

  8. Remediation consultation

    A review session with your team explaining root causes and helping prioritise the remediation work.

  9. Retesting

    Remediated findings are tested again to confirm the fix is effective and has not created a new problem.

  10. Final closure report

    A final statement of every finding’s status, suitable for internal audit or external review files.

We test only with written authorisation and only within the agreed scope.

Standards and frameworks

We use the following open standards as a coverage framework and a common language for results. Referencing them does not imply we are accredited by, or partnered with, the organisations that publish them.

Versions verified against the official sources on .

How we communicate severity

We rate findings using CVSS v4.0 and always show which factors produced the score, alongside a plain description of the impact in your specific context.

RatingWhat it means in our reportsSuggested response
Critical Demonstrably exploitable, leading to system compromise or broad access to sensitive data. Reported immediately during testing; treat as the highest remediation priority.
High Exploitable with significant impact on confidentiality, integrity or availability. Plan remediation into the nearest release cycle.
Medium Exploitable under certain conditions, or with more limited impact. Schedule within your normal remediation backlog.
Low Limited impact, or dependent on conditions that are unlikely to occur. Address opportunistically.
Informational Not a vulnerability in itself, but an improvement that reduces overall risk. Feed into internal standards and hardening work.

Limitations we always state

  • A penetration test is an assessment at a point in time, within a defined scope. It is not a guarantee that a system contains no vulnerabilities.
  • Our reports always record what was out of scope, and anything that could not be fully tested because of time, access or risk to production services.
  • We take no action against systems not covered by written authorisation, even when those systems are connected to the target.
  • Findings and evidence are stored and delivered over encrypted channels and destroyed on the schedule agreed in the contract.

Contact

Start with a scoping conversation

Tell us roughly what you need tested and we will come back with a proposed scope, duration and testing approach.

We test only with written authorisation and only within the agreed scope.