A clear process from first call to fixed findings.
Every engagement follows the same seven steps, so you always know what's happening and what comes next. Choose a one-off test or ongoing testing. One person handles the whole process from start to finish.
Request a Scoping CallTwo ways to work together
Both use the same process. The difference is how long we stay involved.
One-off testing
A single, complete test of your systems, with follow-up checks to confirm your fixes worked.
The full seven-step process once, plus a set number of retests, agreed in scope, to verify remediation.
A compliance requirement, a new application or environment, or a first look at where you stand.
Continuous testing
Regular testing throughout the year, so new problems get caught as your systems and the threats change.
Quarterly testing, unlimited retests, and proactive outreach. When a new attack or exploit appears that affects systems like yours, I contact you right away and ask permission to retest.
Organizations that change often, handle sensitive data, or want ongoing assurance instead of a once-a-year snapshot.
The seven steps
Each step explained in plain language first, then in technical detail for your IT team.
- Scope We agree on what's being tested, when, and what's off limits, in writing. Target definition, in-scope and out-of-scope assets, testing windows, rules of engagement, emergency contacts, and written authorization.
- Recon I gather what an outsider could learn about you without touching your systems. Passive open-source intelligence, domain and subdomain discovery, technology fingerprinting, and exposed employee and infrastructure details.
- Enumeration I map out what's there: systems, services, logins, and entry points. Active discovery of hosts, ports, services, application endpoints, users, and versions to identify the attack surface.
- Testing I try to break in and get around your defenses, the way a real attacker would. Manual exploitation and abuse-case testing against the enumerated attack surface, within the agreed scope and rules of engagement.
- Validation I confirm each finding is real and measure how much damage it could cause, so you aren't chasing false alarms. Reproducing each issue, confirming exploitability and impact, removing false positives, and assigning severity with supporting evidence.
- Reporting You get a clear report, and I walk your team through it. An executive summary for leadership, plus detailed technical findings with severity, evidence, reproduction steps, and recommended fixes.
- Remediation Your team fixes the problems, and I retest to confirm they're actually closed. Fix guidance and questions support, followed by retesting of remediated findings to verify closure and update the report.
What you can expect from me
One point of contact
The same person scopes, tests, and reports. There are no handoffs, and nothing gets lost between teams.
Written authorization first
Nothing starts until we agree on scope in writing, and I tell you right away if I find something critical.
Common questions
What is the difference between one-off and continuous penetration testing?
One-off testing runs the full seven-step process once, plus a set number of retests agreed in scope to verify your fixes. Continuous testing repeats the full process every quarter, includes unlimited retests, and adds proactive outreach when a new attack or exploit affects systems like yours.
How often should a business have security testing done?
If your systems stay mostly the same, a yearly test is often enough. If you are growing or changing quickly, every quarter or twice a year works better, plus a test after major changes such as a new website, product, or system migration, and before big moments like a large customer contract or funding round.
Will I work with the same person throughout?
Yes. One person scopes the work, runs the testing, writes the report, and walks your team through it. There are no handoffs between sales and technical staff.
Could testing disrupt our systems?
Nothing starts until scope and rules of engagement are agreed in writing. Actions that could take systems down are avoided, agreed test data is used instead of real records, anything critical is reported right away, and changes made during testing are undone.
What do we get at the end of a test?
A report with an executive summary for leadership and detailed findings for your technical team. Each finding includes severity, evidence, reproduction steps, and a recommended fix. You also get a walkthrough of the results and retesting to confirm fixes.
Is a penetration test the same as a compliance certification?
No. Security testing supports your compliance efforts and gives you dated, documented proof of testing, but it is not a certification or a legal opinion.
Not sure which option fits?
Tell me about your environment and how often it changes, and I'll recommend one.
Get in Touch