From the first call to the retest: what we need from you, what you get at the end, and a few things people don't expect.
If you've never had a penetration test, the process can look a bit opaque. You give someone access (or don't), they "hack" things for a week, and a PDF turns up. Here's roughly how it goes when you work with us, so there are fewer surprises.
Scoping
We start with a call to understand what you actually want to find out. "Test everything" isn't a scope. "Can someone on the internet get into our customer portal?" is. So is "if one laptop gets infected, how far can an attacker get?"
From there we agree what's in scope (IP ranges, URLs, applications, the office network), what's out, the testing window, and how much we're told up front. For web apps, testing with a normal user account is usually the best value. Starting from nothing sounds more realistic, but you end up paying for days of work that a real attacker would skip with one phishing email.
Paperwork
Before anything starts, you sign a written authorisation listing the targets and dates. It protects both sides. If you're on a hosting provider or cloud platform, check their testing policy; most allow it, some want notice.
Testing
We keep a named contact on your side updated while we test. If we find something serious, like an exposed database or a way into an admin panel, we tell you then, not in the report two weeks later.
We're careful, but testing does mean sending unusual traffic at your systems. Make sure backups are current and that someone who can restart a service is reachable during the window.
The report
There's a short summary for management and a technical section for whoever does the fixing. Each finding covers what we did, how to reproduce it, why it matters for your business, and how to fix it. We give a severity rating, and separately we tell you what we'd fix first. Those aren't always the same.
What you won't get is a hundred pages of scanner output with a logo on top. Anything an automated tool flagged has been checked by hand before it goes in.
Retest
Once you've fixed things, we retest those findings and update the report. If a customer or auditor has asked you for evidence, this is usually the part they care about.
Things people don't expect
The most serious finding is often something simple: a default password, or an old test server nobody remembered was still online.
We'd also rather you told your IT team the test is happening. Unannounced testing has its place (that's what a red team exercise is for), but for a normal pentest, having IT involved means fewer false alarms and more useful results.
If you're thinking about a test and want to talk it through, send us a message.





Comments (0)
No public comments yet.