ENGAGEMENT METHODOLOGY

See how we map boundaries, execute security reviews under NDA, and support your engineering team through remediation.

Best suited forProcurement and legal teams before contracting
Primary outcomeWritten scope before work begins
ScopeDiscovery call and business-question definition
Typical timingConfirmed after the scoping call

Is this right for you?

When to choose this service

Procurement and legal teams before contractingSystem owners controlling production riskLeadership evaluating supplier maturityTechnical teams planning access and remediation

What we cover

  • Discovery call and business-question definition
  • Confidentiality agreement and supplier due diligence
  • Technical scope, assumptions, exclusions and statement of work
  • Production rules, authorised actions and emergency stop
  • Secure exchange of access and evidence
  • Status updates, early critical-finding escalation and change control
  • Quality review of executive and technical reporting
  • Results workshop, remediation support and retest
  • Data return or deletion and engagement closure

What you receive

  • Written scope before work begins
  • One accountable contact on each side
  • Secure channel for sensitive data
  • Agreed critical-finding notification route
  • Traceable scope changes
  • Closure confirmation for data retention or deletion

Delivery flow

From scope to a verified result

  1. 1. Discovery & Scoping: We define business goals, map exact system boundaries (Rules of Engagement), and execute an NDA.

  2. 2. Execution & Testing: Our engineers run technical assessments or compliance gaps with zero impact on live operations.

  3. 3. Risk Analysis & Reporting: Findings are mapped to business impact and presented in a 2-tiered report (Executive / Technical).

  4. 4. Remediation & Retesting: We review fixes with your developers and conduct a free retest within 30 days to confirm closure.

Before we start

Frequently asked questions

Where should we start?

Start with the business objective, critical services and the main uncertainty. A short discovery call establishes whether the right path is governance, testing, monitoring or incident readiness.

Can we begin with a small scope?

Yes. The work can be divided into a priority first stage and a longer roadmap. The first stage still needs to produce a usable decision rather than a generic presentation.

How is our information protected?

Before accessing data, we agree confidentiality, authorised systems, data minimisation, storage, encryption, access control and deletion. The exact terms must be included in the contract and statement of work.

When are testing rules signed?

Before any active action. The rules should cover systems and IPs/addresses, dates, authorised and prohibited techniques, rate limits, contacts, incident procedure and evidence handling.

When is a critical finding reported?

Without waiting for the final report. Criteria and the notification route are agreed before work. The message must support safe action without sending sensitive evidence through an unsuitable channel.

Related next steps