Rules of engagement
The document we sign before any offensive testing. Scope, windows, escalation contacts and stop conditions, with the clauses that matter annotated.
Templates and checklists taken from live engagements rather than written for a download form. No email gate, no drip sequence.
Adapt them freely. Attribution is welcome and not required.
The document we sign before any offensive testing. Scope, windows, escalation contacts and stop conditions, with the clauses that matter annotated.
A four-tier classification your on-call can apply at three in the morning without waking anyone to decide. Maps to NIS2 notification thresholds.
What to have ready before a penetration test starts, so week one is testing rather than access requests.
Three ransomware scenarios with injects, facilitator notes and a scoring sheet. Enough to run a two-hour exercise without a consultant in the room.
Six words that get used loosely in vendor material, and what we mean by them.
Most of the organisations now in scope are not the ones the directive names. They are the suppliers those organisations depend on.
Seven days from initial access to the ransom note, reconstructed from an engagement where the client kept every log.
A migration sequence that does not require freezing delivery or replacing the network you already have.