Fixed-scope penetration testing
Scoped, announced and booked against a date. You know what is being tested, when it happens, and what lands at the end of it before anyone touches a system.
Somebody has asked you for a test.
A SOC 2 or ISO 27001 audit
Your auditor has asked for evidence of penetration testing inside the current period, carried out by a party independent of the team that built the system.
PCI DSS
Cardholder data is in scope, and the standard requires application testing and segmentation testing on a defined cycle.
Cyber insurance
An insurer has made a current test a condition of renewal, or is pricing the policy against the last one you hold.
A customer security review
An enterprise customer will not sign until their vendor questionnaire has a recent third-party test against it.
All four want the same thing on file: a current test, run by someone independent, with the scope and the outcome stated in a form a third party can read.
What we test
Each scope is priced and booked on its own. Take one, or take several across the same window.
External network
Internet-facing infrastructure: perimeter services, exposed management interfaces, and what is reachable before anyone presents a credential.
Internal network
An assumed foothold on the internal estate, then lateral movement, privilege escalation, and the identity paths that join the two.
Web application
Authenticated and unauthenticated testing against application logic, access control between roles, and session handling.
API
The surface as published and as deployed, with authorization checked on every method rather than on the documented path alone.
Mobile
The iOS and Android clients, the data they hold at rest on a device you do not control, and the services behind them.
Cloud configuration
Identity, network and storage configuration in your cloud accounts, read against the access a single compromised principal would inherit.
Operational technology is assessed in a modeled environment. S32 Technologies does not run active testing against live plant, and the rules of engagement say so in writing before anything starts.
Fixed before anyone starts
Every item below is agreed in writing at scoping and does not move once the engagement is booked. That is what fixed scope means here.
What you are handed
Three documents, because the person who fixes the finding and the person who files it are rarely the same person.
Every finding with the evidence behind it, a severity, the affected assets, and remediation written for the team that has to carry it out.
A signed letter stating the scope tested, the dates, the methodology and the outcome. Written to be handed to an auditor, an insurer or a customer without exposing the technical detail.
Once you have remediated, the findings are tested again and the result is confirmed in writing against the original report.
Two different questions.
A fixed-scope test establishes whether a control can be defeated, against systems named in advance, inside a window your team knows about. A RedLane engagement establishes whether your team recognized an operation as an operation, against defenders who were never told.
An auditor is asking the first question. Both are worth answering, and they are scoped, delivered and reported separately.
Questions
Will our auditor accept this?
The summary letter carries the scope, the dates, the methodology and the outcome, which is what an auditor, an insurer or an enterprise customer keeps on file. S32 Technologies is not a member of a testing accreditation scheme and does not claim to be. Where your framework requires an accredited assessor, say so at scoping and we will tell you plainly whether we meet it.
Do you need access to production?
Only where you put it in scope. Testing runs against the environment you name, and where that is production the rules of engagement set the constraints: permitted hours, availability limits, and the conditions under which we stop.
What happens if you find something critical during the test?
Your named contact hears about it when we find it, not when the report lands, with enough detail to act on the same day.
Do we have to run S32 Technologies products?
No. Testing is technology agnostic and runs against the systems you already have. An engagement establishes how your controls performed. It is not a certification of anything S32 Technologies sells.