Resources

The documents we actually use

Templates and checklists taken from live engagements rather than written for a download form. No email gate, no drip sequence.

Toolkit

Four documents worth stealing

Adapt them freely. Attribution is welcome and not required.

Template

Rules of engagement

The document we sign before any offensive testing. Scope, windows, escalation contacts and stop conditions, with the clauses that matter annotated.

6 pages · DOCX Request it
Template

Incident severity scale

A four-tier classification your on-call can apply at three in the morning without waking anyone to decide. Maps to NIS2 notification thresholds.

2 pages · PDF Request it
Checklist

Pre-engagement readiness

What to have ready before a penetration test starts, so week one is testing rather than access requests.

1 page · PDF Request it
Worksheet

Tabletop exercise pack

Three ransomware scenarios with injects, facilitator notes and a scoring sheet. Enough to run a two-hour exercise without a consultant in the room.

14 pages · PDF Request it
Glossary

Terms, defined honestly

Six words that get used loosely in vendor material, and what we mean by them.

Dwell time
How long an intruder is present before detection. The number that matters more than the count of alerts you generated.
Assumed breach
A test that starts from inside, on the premise that perimeter compromise is a question of when. Usually more informative than an external test.
Blast radius
What a single compromised identity can reach. Reducing it is cheaper than trying to prevent every compromise.
Detection engineering
Writing and maintaining detection content as code, against your own estate, rather than accepting vendor defaults.
Double extortion
Encrypting data and threatening to publish what was taken. A good backup answers half of it.
Purple team
Offensive and defensive teams working the same scenario together, so every attack technique leaves a detection behind.