Home / Methodology

Methodology

A UK-lawful attacker simulation.

Nothing starts until you have signed an authorisation letter covering the Computer Misuse Act 1990. After that, six steps, no scope creep, a re-test at the end.

A quiet office floor. The test itself is remote-default; the method is not casual.
A quiet office floor. The test itself is remote-default; the method is not casual.
01

Scoping & authorisation

Assets, identities, hours, out-of-scope, data handling. You sign. We counter-sign. Testing without this is a crime in the UK; we will not do it.

02

Reconnaissance

Attack surface as it really is: DNS, certificates, forgotten hosts, mobile API hosts, cloud metadata. We send you the map before we break things.

03

Discovery

Manual, feature by feature, with two accounts wherever authorisation matters. Tools amplify; they do not decide.

04

Exploitation & proof

Bounded proof. A few rows, a screenshot, a replay script — never a bulk dump of your customers.

05

Reporting

Executive + technical. OWASP / ISO 27001 / NCSC CAF mapping where honest. CVSS v3.1. Plain English for the board pack.

06

Re-test

You patch. We verify every confirmed issue, included in the fee, and issue sign-off.

Standards we map to — not logos we rent

OWASP · ISO 27001 · NCSC CAF · UK GDPR · PCI DSS · Cyber Essentials

We map findings onto the control set you named in the statement of work. We do not print CREST, CHECK or IASME marks we have not earned. If a buyer requires those memberships, we will say so on the first call.

Ready to scope a UK engagement?

A thirty-minute call. Assets, timeline, a quote in pounds sterling.

Request a quote