Scoping & authorisation
Assets, identities, hours, out-of-scope, data handling. You sign. We counter-sign. Testing without this is a crime in the UK; we will not do it.
Home / Methodology
Methodology
Nothing starts until you have signed an authorisation letter covering the Computer Misuse Act 1990. After that, six steps, no scope creep, a re-test at the end.
Assets, identities, hours, out-of-scope, data handling. You sign. We counter-sign. Testing without this is a crime in the UK; we will not do it.
Attack surface as it really is: DNS, certificates, forgotten hosts, mobile API hosts, cloud metadata. We send you the map before we break things.
Manual, feature by feature, with two accounts wherever authorisation matters. Tools amplify; they do not decide.
Bounded proof. A few rows, a screenshot, a replay script — never a bulk dump of your customers.
Executive + technical. OWASP / ISO 27001 / NCSC CAF mapping where honest. CVSS v3.1. Plain English for the board pack.
You patch. We verify every confirmed issue, included in the fee, and issue sign-off.
Standards we map to — not logos we rent
We map findings onto the control set you named in the statement of work. We do not print CREST, CHECK or IASME marks we have not earned. If a buyer requires those memberships, we will say so on the first call.
A thirty-minute call. Assets, timeline, a quote in pounds sterling.
Request a quote