Skip to content

Checklist

Checklist before a pentest

The meeting pays off when the scenario is already on the table. Without that, the first call becomes an inventory. With it, you leave with a slice and a next step.

Surface

Which applications are in. Which APIs. Whether there is a mobile app. Whether cloud is in — and which accounts. Production, staging or both.

What is at stake: customer data, payments, tenants, an internal panel.

Limits

What is off-limits. The time window. Whether there is a release blackout. A channel for a critical issue mid-test.

A recent incident changes the slice. A previous pentest: bring what stayed open — not the whole PDF.

Access

Test credentials are discussed after the slice. We do not ask for admin, a VPN or a source dump in the first email.

An NDA when needed. Who signs on your side. Who receives the report.

Format

One-off or ongoing. Whether you need a retest. Whether leadership only wants a PDF or the team will sit in the delivery.

With that on the table, you can compare proposals. Without it, you compare numbers that do not describe the same job.

Guides

Next step

Want to book a meeting?

Tell us the company size and what needs to be protected — the system, the environment, what is at stake. From the call, we assess the scenario and build the work within your scope.