Scope and risk map
Agreed boundaries before testing begins.
- List of assets and owners
- Testing rules and time window
- Business priorities
Assets / permissions / scenarios
You know what the assessment covers and where its limits are.
We analyse code and architecture, test authorised environments, control access, monitor systems, design backups and help respond to incidents.
described in business terms
have an owner and evidence
is tested, not assumed
We examine the agreed applications, access and configuration in terms of their real business impact. The findings become a sequence of fixes and a way to verify that each problem has been resolved.
A list of vulnerabilities is not enough to make a decision. What matters is what you could lose, how easily a weakness could be exploited and who is responsible for fixing it.
We establish what needs protection first.
We map applications, data and dependencies. We identify the impact of downtime, loss of access or disclosure of information.
What would hurt the business most?
We check who can perform which actions.
We analyse roles, privileged accounts and authentication. We review how access is granted and revoked.
Does access match the actual need?
We verify the agreed misuse scenarios.
We test the application and its environment within approved boundaries. Each finding includes the conditions needed to reproduce it.
Which weaknesses can be exploited?
We help turn the report into completed tasks.
We agree priorities, verification methods and responsibilities. We also assess readiness to restore operations.
Does the team know what to do when a problem is found?
Before starting, we define the scope, permissions and testing rules. You receive a description of the risks and specific tasks for the people responsible for the system.
Agreed boundaries before testing begins.
Assets / permissions / scenarios
You know what the assessment covers and where its limits are.
Problems described clearly enough to assess them.
Finding / impact / recommendation
The technical team can plan specific changes.
Actions prioritised according to risk.
Task / owner / acceptance criterion
System owners know where to start.
Rechecking the identified issues.
Retest / status / further recommendations
You have confirmation of which fixes have been completed.
The testing scope and the asset owner's consent are agreed before work begins. An audit does not guarantee complete security or constitute certification. Remediation and retesting are defined as specific parts of the engagement.
We choose tools to suit the scope and available data.
Protection and traffic control with an appropriate configuration.
Change control and code security review.
Identity and access review in Microsoft environments.
You know what we are working on, when we need your input and what moves to the next stage. The schedule follows the agreed scope.
We define the assets, owners, risks and permitted actions.
You confirm permissions and contact people.
Stage outcomeApproved testing scope.
We agree test accounts, the work window and how to report issues.
You provide access and the required backups.
Stage outcomeReady for safe testing.
We test within agreed boundaries and document the findings.
You remain available when significant events occur.
Stage outcomeVerified issues and evidence.
We explain the impact of the findings and recommend an order for fixing them.
You assign task owners.
Stage outcomeReport and action plan.
We check the fixes within the agreed scope.
You provide access to the updated environment.
Stage outcomeRemediation status and remaining recommendations.
Case study / Security
There are no published case studies in this language yet.
The full catalogue remains available on the work page.
The scope should fit your business needs, available data and capacity to implement. These questions help define the project's boundaries.
The risk depends on the scope. We agree methods, the work window, an emergency contact and conditions for stopping a test. Some checks can be performed in a test environment.
Only assets explicitly included in the scope. We select them first according to business importance, exposure and available time.
We can agree remediation work or support your team. Assessment, implementation and verification are separate stages.
We do not present an audit as a guarantee or certification. The report documents the tests performed, the findings and the limits of the assessment.
Before starting, we agree the recipients, delivery channel and rules for storing materials. Access is restricted to the people responsible.
That depends on the system and its risks. Monitoring, updates, backups and incident handling are separate tasks that we define after assessing your needs.
Describe the system, data and reason for the assessment. We will propose a safe scope, methodology and next step.
We respond with a concrete recommendation by the end of the next business day.
Step 1 / 4