A penetration test is an authorized, simulated attack: our testers try to get into your systems the way a real attacker would, so you can fix the weaknesses before someone else finds them. The scope is the written agreement on what we test, how and when.
What are we protecting?
We start from your work, not from the network diagram: which services matter most, which data would do harm if it leaked, and which regulations apply, such as the NCA's controls. The answers decide where the testing time goes.
What is in scope?
We list the targets one by one: web applications, mobile apps, internal and external networks, cloud environments, and operational technology such as industrial control systems (OT/ICS). Anything that is not on the list is not touched.
How much do we know going in?
- Black box: we start with no inside information, like an attacker from outside.
- Grey box: we get an ordinary user account, like an employee or a customer.
- White box: we see the designs and the code, so the same time finds more issues.
What are the rules?
The rules of engagement set the testing windows, the systems that must never go down, the contacts on both sides, and what happens when we find a critical issue: we stop and call you, so it never waits for the report.
What comes after?
You receive a report with every finding, how serious it is and the steps to fix it, in Arabic, English or both.
