S32TECHNOLOGIES
RedLane · Fixed scope

Fixed-scope penetration testing

Scoped, announced and booked against a date. You know what is being tested, when it happens, and what lands at the end of it before anyone touches a system.

Scope an engagementRedLane

Why you are here

Somebody has asked you for a test.

A SOC 2 or ISO 27001 audit

Your auditor has asked for evidence of penetration testing inside the current period, carried out by a party independent of the team that built the system.

PCI DSS

Cardholder data is in scope, and the standard requires application testing and segmentation testing on a defined cycle.

Cyber insurance

An insurer has made a current test a condition of renewal, or is pricing the policy against the last one you hold.

A customer security review

An enterprise customer will not sign until their vendor questionnaire has a recent third-party test against it.

All four want the same thing on file: a current test, run by someone independent, with the scope and the outcome stated in a form a third party can read.

What we test

Each scope is priced and booked on its own. Take one, or take several across the same window.

External network

Internet-facing infrastructure: perimeter services, exposed management interfaces, and what is reachable before anyone presents a credential.

Internal network

An assumed foothold on the internal estate, then lateral movement, privilege escalation, and the identity paths that join the two.

Web application

Authenticated and unauthenticated testing against application logic, access control between roles, and session handling.

API

The surface as published and as deployed, with authorization checked on every method rather than on the documented path alone.

Mobile

The iOS and Android clients, the data they hold at rest on a device you do not control, and the services behind them.

Cloud configuration

Identity, network and storage configuration in your cloud accounts, read against the access a single compromised principal would inherit.

Operational technology is assessed in a modeled environment. S32 Technologies does not run active testing against live plant, and the rules of engagement say so in writing before anything starts.

Fixed before anyone starts

Every item below is agreed in writing at scoping and does not move once the engagement is booked. That is what fixed scope means here.

ScopeThe systems in scope named by host, domain or account, and everything excluded named just as explicitly.
Window and report dateThe testing window and the date the report is delivered, both agreed before the engagement is booked.
Rules of engagementPermitted techniques, availability constraints, out-of-hours limits, and the conditions under which testing stops.
AuthorizationSigned authority from someone entitled to give it, plus written confirmation from your hosting provider where their terms require it.
Named contactsOne technical contact on your side and one engagement lead on ours, both reachable for the whole window.
HandlingWhere findings are held, who may read them, and the retention period for the working data.

What you are handed

Three documents, because the person who fixes the finding and the person who files it are rarely the same person.

01
Technical report

Every finding with the evidence behind it, a severity, the affected assets, and remediation written for the team that has to carry it out.

02
Summary letter

A signed letter stating the scope tested, the dates, the methodology and the outcome. Written to be handed to an auditor, an insurer or a customer without exposing the technical detail.

03
Retest confirmation

Once you have remediated, the findings are tested again and the result is confirmed in writing against the original report.

Two different questions.

A fixed-scope test establishes whether a control can be defeated, against systems named in advance, inside a window your team knows about. A RedLane engagement establishes whether your team recognized an operation as an operation, against defenders who were never told.

An auditor is asking the first question. Both are worth answering, and they are scoped, delivered and reported separately.

How a RedLane engagement runs

Questions

Will our auditor accept this?

The summary letter carries the scope, the dates, the methodology and the outcome, which is what an auditor, an insurer or an enterprise customer keeps on file. S32 Technologies is not a member of a testing accreditation scheme and does not claim to be. Where your framework requires an accredited assessor, say so at scoping and we will tell you plainly whether we meet it.

Do you need access to production?

Only where you put it in scope. Testing runs against the environment you name, and where that is production the rules of engagement set the constraints: permitted hours, availability limits, and the conditions under which we stop.

What happens if you find something critical during the test?

Your named contact hears about it when we find it, not when the report lands, with enough detail to act on the same day.

Do we have to run S32 Technologies products?

No. Testing is technology agnostic and runs against the systems you already have. An engagement establishes how your controls performed. It is not a certification of anything S32 Technologies sells.