SECOMPSSECOMPS
Home/Methodology
How we work

Scope. Attack. Report. Retest.

Four phases, no ambiguity, no surprise invoices. This is exactly what happens between the day you sign and the day you hand an attestation letter to your customer.

At a glance

Phase 01
Scope, 2 to 3 working days
Phase 02
Attack, 1 to 3 weeks
Phase 03
Report, 3 to 5 working days
Phase 04
Retest, included as standard
Escalation
Critical findings the same day we prove them
01Principle

Every finding exploited, never just flagged.

Automated tools are good at coverage and bad at judgement. We run them first so no obvious surface is missed, then people take over for the work tools cannot do: chaining low-severity issues into high-severity outcomes, reasoning about authorisation, and abusing functionality that is working exactly as designed.

The practical consequence is that our reports are shorter than scanner exports and considerably more useful. We do not report a theoretical critical. If we could not demonstrate it, it is documented as an observation with that stated plainly, so your team can spend remediation effort on things that are real.

02Phases

Scope. Attack. Report. Retest.

Scope

We define the attack surface with you: assets in and out of scope, credentials and roles, environments, testing windows, excluded actions and an emergency contact. You receive a fixed price and a start date, not an hourly estimate and a range. If we think you are buying the wrong engagement, we say so here rather than after invoicing.

Attack

Automated coverage first, then manual exploitation by the assigned testers. You get a kickoff call, a mid-engagement checkpoint, and immediate contact if something critical surfaces. We work to the rules of engagement agreed in phase one and we do not expand scope without asking.

Report

Three audiences in one document: an executive summary for leadership, technical findings with proof-of-concept evidence and reproduction steps for engineers, and a control-mapping annex for auditors. Draft first, walkthrough call, then final, so factual corrections happen before the report is issued rather than after.

Retest

Once your team has remediated, we verify each fixed finding and reissue an updated attestation letter you can share with customers and auditors. This is included in the engagement fee. Findings that were not fixed are recorded as still open rather than quietly dropped.

03Escalation

Same-day escalation

If we prove something an attacker could exploit today, you hear about it that day, by whatever channel we agreed at scoping. You get the finding, the evidence and enough detail to act immediately. Holding a live critical for three weeks so it can appear in a polished document is a practice we consider indefensible.

04Boundaries

What we will not do.

  • Denial-of-service testing, unless you explicitly request it in writing and we agree a window.
  • Social engineering against your staff, unless separately scoped and authorised by someone senior enough to authorise it.
  • Testing systems outside the agreed scope, even when they are visibly reachable and interesting.
  • Retaining your data after the engagement beyond the retention period agreed in the contract.
  • Padding the report with informational findings to make the engagement look larger than it was.
05Standards

Frameworks we map to.

Our methodology maps to established public standards so your auditor and your engineers can both follow it: OWASP Top 10 and OWASP WSTG for web applications, OWASP API Security Top 10 for APIs, OWASP MASVS and MASTG for mobile, PTES and NIST SP 800-115 for network engagements, and MITRE ATT&CK for describing attacker behaviour in internal testing.

These are methodology references, not accreditations. We list them because they tell you how we work, and because a vendor who cannot name their methodology usually does not have one.

Want this applied to your environment? Let's scope it.

Twenty minutes with a security engineer. Fixed quote and a start date.