Methodology
Methodology
We work through a defined sequence and document each stage, so results are traceable and repeatable — by our own team and by an external reviewer.
Engagement phases
-
Scoping and authorisation
Identify target systems, environments, testing window and contacts, then obtain written authorisation before any testing begins.
-
Rules of engagement
Agree what is and is not permitted — including availability-affecting tests, emergency contact channels, and the conditions under which we stop immediately.
-
Threat modelling
Understand the architecture, trust boundaries and valuable assets, so testing time is spent where it produces the most useful result.
-
Manual and tool-assisted testing
Tools map the attack surface broadly; manual testing goes deep where understanding the application’s context is what actually finds the flaw.
-
Exploit validation in the authorised environment
Demonstrate that a finding is genuinely exploitable within the authorised environment, separating real risk from theoretical risk.
-
Impact analysis
Assess business impact in your context rather than relying on a base severity score alone.
-
Evidence-backed reporting
Every finding carries reproduction steps, evidence, a CVSS severity rating and specific remediation guidance.
-
Remediation consultation
A review session with your team explaining root causes and helping prioritise the remediation work.
-
Retesting
Remediated findings are tested again to confirm the fix is effective and has not created a new problem.
-
Final closure report
A final statement of every finding’s status, suitable for internal audit or external review files.
We test only with written authorisation and only within the agreed scope.
Standards and frameworks
We use the following open standards as a coverage framework and a common language for results. Referencing them does not imply we are accredited by, or partnered with, the organisations that publish them.
| Standard | Referenced version |
|---|---|
| OWASP Web Security Testing Guide | 4.2 |
| OWASP Application Security Verification Standard | 5.0.0 |
| OWASP Top 10 | 2025 |
| OWASP API Security Top 10 | 2023 |
| OWASP MASVS | 2.1.0 |
| OWASP MASTG | 2.0.0 |
| CVSS | 4.0 |
Versions verified against the official sources on .
How we communicate severity
We rate findings using CVSS v4.0 and always show which factors produced the score, alongside a plain description of the impact in your specific context.
| Rating | What it means in our reports | Suggested response |
|---|---|---|
| Critical | Demonstrably exploitable, leading to system compromise or broad access to sensitive data. | Reported immediately during testing; treat as the highest remediation priority. |
| High | Exploitable with significant impact on confidentiality, integrity or availability. | Plan remediation into the nearest release cycle. |
| Medium | Exploitable under certain conditions, or with more limited impact. | Schedule within your normal remediation backlog. |
| Low | Limited impact, or dependent on conditions that are unlikely to occur. | Address opportunistically. |
| Informational | Not a vulnerability in itself, but an improvement that reduces overall risk. | Feed into internal standards and hardening work. |
Limitations we always state
- A penetration test is an assessment at a point in time, within a defined scope. It is not a guarantee that a system contains no vulnerabilities.
- Our reports always record what was out of scope, and anything that could not be fully tested because of time, access or risk to production services.
- We take no action against systems not covered by written authorisation, even when those systems are connected to the target.
- Findings and evidence are stored and delivered over encrypted channels and destroyed on the schedule agreed in the contract.
Contact
Start with a scoping conversation
Tell us roughly what you need tested and we will come back with a proposed scope, duration and testing approach.
We test only with written authorisation and only within the agreed scope.