Define the business question
Start with what you want to learn. A pre-launch application review, an internal network test, and an assessment of remote access answer different questions. Identify the business process, sensitive information, and consequences of a failure. Use that context to set the technical scope.
Prepare authorisation and access
Document domains, addresses, applications, environments, and exclusions. Confirm ownership and any third-party approval required. Agree test accounts, access levels, testing windows, escalation contacts, and stop conditions. Sensitive or availability-critical systems need explicit discussion.
Agree on useful deliverables
Ask for validated findings with evidence, impact, and remediation guidance. The report should explain limitations and the areas that were not tested. An executive summary helps decision-makers understand priorities, while technical detail helps engineers make the changes.
Plan the work after the report
Assign owners and target dates to the findings. Some issues need configuration changes; others need architectural or process changes. Agree how retesting will work and how unresolved risks will be tracked. A test is most useful when its output becomes a managed improvement plan.
Further reading
Put the guidance to work
Find exploitable weaknesses in your networks, applications, APIs, and infrastructure before they become incidents.
Penetration testing