Skip to content

METHODOLOGY

Audit methodology in five phases

We agree the scope in writing before any testing starts. Exploitation is manual and stops as soon as impact is proven, leaving your production systems untouched.

5Phases with a signed deliverable
1Point of contact throughout
0Phases subcontracted

Phase by phase

  1. Scope

    Assets included, assets excluded and the rules of engagement. Any later change to the scope is documented in writing before it takes effect.

  2. Reconnaissance

    Domains, subdomains, services and exposed panels, including the ones missing from your inventory.

  3. Exploitation

    Every vulnerability is exploited until its impact is proven, within the limits set in the rules of engagement. Testing stops before causing any damage.

  4. Report

    CVSS scoring, reproduction steps and a prioritised remediation plan. The report is presented in a review session with your team.

  5. Retest

    The retest of every fix is part of the engagement. The final status of each finding goes into a closure report signed by both sides.

Manual, verified exploitation: scanner output is not a finding.

DELIVERABLES

What the report contains

Two layers in one deliverable: the executive summary the risk committee reads and the technical detail your team works from.

No.DeliverableWhat it contains
01Executive summaryBusiness risk on a single page, free of technical jargon and ready to attach as evidence.
02CVSS scoringVector and severity justified finding by finding, with the exploitation chain behind each score.
03Working proof of conceptRequest, steps and evidence, so your team can reproduce the flaw with the report in hand.
04Remediation planThe fixes, ranked by impact and effort.
05Verification retestA new test on every fix applied, recorded in the closure report.

Frequently asked questions

Can the audit affect service availability?

No. Exploitation is manual and stops before any damage is caused: the vulnerability is proven without affecting the service. Destructive testing is excluded unless authorised in writing and run in a prepared environment.

What happens if a critical finding appears during the audit?

Critical findings are reported immediately through the channel agreed in the rules of engagement, together with the minimum containment steps to reduce the risk. Notification does not wait for the final report.

Who does the audit?

The Lapsor team runs it from start to finish, and the same team reports on HackerOne, Bugcrowd and YesWeHack. The OSCP, CRTO and eWPTX certifications are held by the people who run the audit. No part of the work is subcontracted.

Is the report valid for ENS or ISO 27001?

We prepare the report with the technical evidence these audits usually ask for: CVSS scoring, reproduction steps, evidence, remediation and a separate executive summary. The report can be submitted as evidence of the security testing carried out, although final acceptance rests with your auditor.

Do you sign an NDA?

Yes. We sign it before you send us any data and we can work from your own template. The report goes only to the recipients you name, and the NDA covers evidence storage, retention and destruction. Any analysis we publish is anonymised and needs your prior approval.

Request a proposal with the scope defined

Tell us which assets you want tested. We reply within 24 hours.

Request an auditCall