← Back to services

Project page

Penetration Testing Project

Every pentest we run is a managed project with a written brief, a fixed timeline, defined deliverables, and a dashboard you can check at any point. Manual testing by certified consultants, never a scanner dump.

How the engagement runs

  • Mutual NDA signed before any work begins
  • Written rules of engagement, testing windows, and escalation contacts
  • Manual exploitation by certified consultants (OSCP, CEH, ISO 27001 LA)
  • Testing aligned to OWASP Top 10, OWASP ASVS, PTES, and NIST SP 800-115
  • Critical findings escalated within 48 hours of discovery
  • All evidence destroyed or returned at project close

Project deliverables

  • Full technical report with reproduction steps and evidence for every finding
  • Executive summary written for boards, clients, and auditors
  • CVSS v3.1 scored findings with business impact and remediation priority
  • Attack surface inventory of everything discovered in scope
  • Critical issue advisories delivered within 48 hours of discovery
  • Remediation plan with effort estimates and suggested owners
  • Free retest of all confirmed findings within 30 days
  • Attestation letter you can share with customers and auditors

Project timeline

A standard engagement runs about twelve working days from authorisation to debrief, with a free retest inside thirty days.

  1. Scope call & authorisation

    1 dayDay 0

    Free scope call, mutual NDA signed, targets confirmed, rules of engagement and testing windows agreed in writing.

    Deliverable: Signed NDA and rules of engagement

  2. Reconnaissance & mapping

    2-3 daysDays 1-3

    Attack surface discovery, service enumeration, technology fingerprinting, and credential exposure checks against the agreed scope.

    Deliverable: Attack surface inventory

  3. Manual exploitation

    5 daysDays 3-8

    Hands-on testing by certified consultants covering authentication, authorisation, business logic, injection, and configuration weaknesses. No reliance on automated scanners.

    Deliverable: Live findings feed with evidence

  4. Critical notification

    Within 48 hoursContinuous

    Any critical or high risk issue is reported to your named contact within 48 hours of discovery, before the report is written.

    Deliverable: Critical advisory notes

  5. Reporting

    3 daysDays 8-11

    Findings written up with reproduction steps, business impact, CVSS ratings, and prioritised remediation guidance. Executive summary written for non technical readers.

    Deliverable: Full pentest report and executive summary

  6. Debrief & remediation support

    1 dayDay 12

    Walkthrough session with your engineering and leadership teams, remediation owners assigned, questions answered.

    Deliverable: Debrief session and remediation plan

  7. Free retest

    2 daysWithin 30 days

    Once fixes are deployed we retest every confirmed finding and reissue the report with updated status.

    Deliverable: Retest report and attestation letter

Project brief

Give us the scope and we reply within one business day with a proposal, NDA, and a proposed testing window. Nothing is tested without your written authorisation.