Skip to content
CISO Marketplace Services

Methodology

Rigor you can audit.

Security testing is a controlled intrusion into your business. This is how we keep it controlled, repeatable and useful.

Rules of engagement

Agreed in writing before a single packet.

Written authorization

No testing starts without a signed SOW and rules of engagement naming the systems, the windows and who can authorize changes.

Out-of-bounds list

Systems you can't risk (production databases, safety systems, third-party assets you don't own) are excluded in writing.

Stop-work channel

A named contact on each side who can halt testing at any time, for any reason.

Critical escalation

An exploitable critical finding is reported to your named contact when it is confirmed, not held for the final report.

Non-destructive by default

Denial of service, data destruction and persistence beyond the engagement are excluded unless you authorize them explicitly.

Clean-up

Accounts, implants and artefacts created during testing are removed and listed in the report.

Standards

Industry frameworks, not house rules.

Every engagement is planned against a public standard, so your auditors, insurers and customers can see what was tested and how.

PTESPenetration Testing Execution Standard: the phases of every network test.
OWASP WSTG / ASVSWeb application testing and the verification level we test against.
OWASP MASVSMobile application security verification.
OWASP API Top 10API-specific authorization and business-logic flaws.
OWASP LLM Top 10Application-layer risks in LLM apps and agents.
MITRE ATT&CKAdversary techniques for red team planning and reporting.
MITRE ATLASAdversary techniques against AI and ML systems.
NIST SP 800-115Technical guide to information security testing.
CVSS v4.0Severity scoring, adjusted for your environment.

Process

The six steps of every engagement.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Your data

How we handle what we find.

Least data

We prove access without bulk-copying your data. Evidence is redacted to what the finding needs.

Encrypted at rest and in transit

Findings, evidence and reports are stored encrypted and delivered through the client portal.

Confidentiality

Every engagement is covered by the confidentiality terms of the Master Services Agreement.

finding / EXT-07Critical

Unauthenticated file read on VPN appliance exposes session tokens

CWE-22 · ATT&CK T1190

Impact

Session tokens for active users can be read remotely, giving an authenticated foothold on the internal network without credentials.

Evidence

$ curl -sk https://vpn.target/…/../../session
HTTP/1.1 200 OK
session=9f2c…e71a  user=j.doe  ✓ valid

Remediation

Apply the vendor patch, invalidate all active sessions, and restrict the management interface to the admin network.

Sample finding, illustrative

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor