Skip to content
Michal Rajecký

00.3


Methodology

The same sequence every engagement, so you know what happens and when.

SCOPING

We agree what is in scope and what is not, how many roles exist, whether the API is included, and what a realistic time box looks like. The number moves with the answers, so this comes before any quote.

AUTHORISATION

Written authorisation from someone entitled to give it, naming the assets, the window, and the limits. Testing does not start without it. If the asset sits on infrastructure you do not own, the provider may need to authorise it too.

RULES OF ENGAGEMENT

Contact points on both sides, an escalation path for anything urgent, agreed handling of any data encountered, and what to do if something breaks. Denial of service and social engineering are out of scope unless explicitly agreed.

TESTING

Manual testing with tooling where tooling helps. Every candidate finding is investigated by hand to establish whether it is exploitable and how far it reaches. Anything critical is reported while testing is still running, not held back for the report.

REPORTING

An executive summary that a non technical owner can act on, and technical findings with CWE, a CVSS 3.1 vector, root cause, demonstrated impact, affected components and step by step remediation.

REMEDIATION

A debrief call to walk through the findings, and questions answered while your developers work through the fixes.

RETEST

One retest included. Fixed findings are re-verified and the report is reissued with their status updated.


ALIGNMENT

OWASP WSTG
The web application testing checklist that drives coverage.
PTES
Engagement structure, from pre engagement interaction through reporting.
NIST SP 800-115
Technical guide to information security testing and assessment.
NÚKIB
The Czech national cyber security authority publishes its own penetration testing methodology. Engagements are aligned to it where it applies.