01Authorization, target ownership, rules of engagement, and safety
Provide several domains, cloud resources and supplier dependencies, plus a vague request to test everything. Ask the person to establish what can actually be authorized and what must remain untouched.
Confirm: The person verifies the legal entity, asset owner and authority chain rather than treating credentials or public reachability as consent; identifies third-party infrastructure, shared tenancy, managed services and platform terms; names exact FQDNs, IP ranges, applications, APIs, accounts, environments, builds and excluded assets; records start, end, timezone and test source identities; distinguishes vulnerability scanning, penetration testing, code review, adversary simulation, social engineering, physical, wireless, denial-of-service and disclosure activity; requires explicit inclusion for techniques with different harm or consent; defines production approval, maintenance window, backups, restoration, monitoring coordination, data limits, rate limits, prohibited actions, emergency contacts, critical escalation, stop triggers and scope-change authority; rejects ambiguous or expired authorization; and records an out-of-scope dependency as a limitation or requests approval without touching it.
02Threat-informed hypotheses, safe execution, and target-state evidence
Provide a web application, API or infrastructure target with a stated security objective, a test account and a mix of scanner alerts. Ask for a test plan and the smallest useful proof.
Confirm: The person maps the target architecture, trust boundaries, identities, entry points, data flows and exposed versions; chooses a relevant threat or security property rather than exhausting a checklist blindly; combines current requirements, weakness classes and adversary techniques without claiming they define complete coverage; records hypothesis, prerequisite, test data, expected secure behavior and abort condition; confirms target identity and build immediately before action; uses controlled accounts and synthetic data where possible; sets safe concurrency and payload bounds; recognizes state-changing, destructive, costly and availability-sensitive operations; does not pivot, persist, alter logs or collect unrelated data; captures request, response, command, log, trace, screenshot or state delta with time and tester identity; repeats only enough to establish reproducibility; and labels an unavailable, blocked, inconclusive or false-positive test honestly.
03Finding validation, severity, client risk, reporting, and escalation
Provide a high scanner score with weak evidence, a low-scored authorization flaw on a critical workflow, duplicates across assets and a live critical condition. Ask what becomes a reportable finding and how it reaches owners.
Confirm: The person independently validates automated output; identifies the affected asset, build, endpoint, role and configuration; states prerequisite, technique, observed security effect and evidence; separates the weakness, vulnerability instance, attack path and business consequence; distinguishes confirmed, suspected, duplicate, accepted, invalid and untested states; records confidence and limitation; maps to a versioned weakness or verification reference where useful; supplies safe reproduction steps and redacted evidence; calculates technical severity with a disclosed vector and inputs when CVSS is requested; does not present technical severity as client risk; adds exposure, exploit evidence, data, safety, customer, regulatory, operational and compensating-control context for an accountable risk owner; escalates critical findings through the agreed live channel; avoids sensational language and exploit publication; and states exactly which systems, identities, methods and time period the conclusion covers.
04Remediation options, retest, disclosure, cleanup, and continuity
Provide a confirmed finding, a proposed patch, an interim control, a supplier dependency, a later build and copied test evidence. Ask how the engagement closes without turning a report into shelfware.
Confirm: The person explains root cause and affected variants without prescribing one unreviewed fix; works with owners on removal, update, configuration, validation, authorization, isolation, monitoring or other controls; records owner, priority, target, dependency, interim protection and accepted exception; preserves the original finding while linking remediation evidence; retests the same prerequisite and security effect on an identified changed build; checks for regression and relevant variants without silently expanding scope; reports fixed, partially fixed, mitigated, not fixed, cannot retest or risk accepted distinctly; returns disclosure and notification decisions to authorized owners and coordinated processes; retains embargo and sensitive details as agreed; revokes accounts and keys, removes payloads and persistence, restores modified state, accounts for copied data and evidence deletion, and records residual artifacts; leaves the client with versioned scope, action, finding, decision, retest and cleanup records another authorized tester can follow.