01 — Authorise and prepare
Agree objectives, system ownership, third-party boundaries, test identities and representative data. Write the rules of engagement before execution. Include the environment version, communication channel and authority to pause activity.
Use written authorisation, agreed environments, synthetic data and named stop authority. Define rate limits, excluded methods, cleanup and escalation before testing. Production activity and supplier systems require explicit permission.
02 — Model the attack path
We distinguish a scanner observation from a validated weakness, usable access from network reachability, and demonstrated impact from an untested possibility.
- Can one customer or tenant read or modify another organisation’s records?
- Can a public application expose a workload identity with excessive internal authority?
- Do segmentation, approval and session-revocation controls stop the agreed attack path?
Use these questions to choose a realistic sequence and a bounded proof point. Explain where an assumed starting position or supplied credential will limit the conclusion.
03 — Execute and observe
Combine approved discovery with manual validation. Keep request rates and actions within the operating plan. Record successful and blocked operations with the identity and context used. Stop at agreed proof rather than expanding access simply because it is technically possible.
04 — Reconstruct the evidence
Reconcile tester observations with application, identity and defence records. Distinguish a response from a confirmed state change, a reachable host from usable authority and an assisted scenario from unaided access. Record clock differences that affect the timeline.
05 — Remediate and retest
Prioritise by the demonstrated path, reachable business operation and control context. Agree owner, due date and acceptance criteria. Separate an executed retest from a future plan, and preserve the findings that remain open.
Primary sources
General information, not a compliance opinion. Confirm legal applicability and testing requirements for your entity and jurisdiction.

