METHODOLOGY
Audit methodology in five phases
We agree the scope in writing before any testing starts. Exploitation is manual and stops as soon as impact is proven, leaving your production systems untouched.
Phase by phase
-
Scope
Assets included, assets excluded and the rules of engagement. Any later change to the scope is documented in writing before it takes effect.
-
Reconnaissance
Domains, subdomains, services and exposed panels, including the ones missing from your inventory.
-
Exploitation
Every vulnerability is exploited until its impact is proven, within the limits set in the rules of engagement. Testing stops before causing any damage.
-
Report
CVSS scoring, reproduction steps and a prioritised remediation plan. The report is presented in a review session with your team.
-
Retest
The retest of every fix is part of the engagement. The final status of each finding goes into a closure report signed by both sides.
Manual, verified exploitation: scanner output is not a finding.
DELIVERABLES
What the report contains
Two layers in one deliverable: the executive summary the risk committee reads and the technical detail your team works from.
| No. | Deliverable | What it contains |
|---|---|---|
| 01 | Executive summary | Business risk on a single page, free of technical jargon and ready to attach as evidence. |
| 02 | CVSS scoring | Vector and severity justified finding by finding, with the exploitation chain behind each score. |
| 03 | Working proof of concept | Request, steps and evidence, so your team can reproduce the flaw with the report in hand. |
| 04 | Remediation plan | The fixes, ranked by impact and effort. |
| 05 | Verification retest | A new test on every fix applied, recorded in the closure report. |
Frequently asked questions
Can the audit affect service availability?
No. Exploitation is manual and stops before any damage is caused: the vulnerability is proven without affecting the service. Destructive testing is excluded unless authorised in writing and run in a prepared environment.
What happens if a critical finding appears during the audit?
Critical findings are reported immediately through the channel agreed in the rules of engagement, together with the minimum containment steps to reduce the risk. Notification does not wait for the final report.
Who does the audit?
The Lapsor team runs it from start to finish, and the same team reports on HackerOne, Bugcrowd and YesWeHack. The OSCP, CRTO and eWPTX certifications are held by the people who run the audit. No part of the work is subcontracted.
Is the report valid for ENS or ISO 27001?
We prepare the report with the technical evidence these audits usually ask for: CVSS scoring, reproduction steps, evidence, remediation and a separate executive summary. The report can be submitted as evidence of the security testing carried out, although final acceptance rests with your auditor.
Do you sign an NDA?
Yes. We sign it before you send us any data and we can work from your own template. The report goes only to the recipients you name, and the NDA covers evidence storage, retention and destruction. Any analysis we publish is anonymised and needs your prior approval.
Request a proposal with the scope defined
Tell us which assets you want tested. We reply within 24 hours.