Skip to main content

Engagement guide

What happens when you work with Cyentrix.

From the first call to the re-test: what we do at each stage, what we need from you, what you get back, and what the words in the report mean. Nothing here requires an account, a download or a licence.

The six stages

Scope. Test. Verify. Report. Remediate. Re-test.

01Scope

A 30-minute call, then a written scope.

We start with a short call to understand your environment and what you are worried about: which systems, how they are exposed, what has changed recently, and any compliance driver behind the request. Within a few working days you receive a written scope and a fixed quote. Nothing starts until you approve it.

You give usthe targets · a technical contact · preferred windows
You getwritten scope · fixed quote · rules of engagement
Typical lead time1–2 weeks from approval to start
02Test

We test everything in scope, in the agreed window.

External work needs nothing from you beyond the target list — no agent, no credentials, no VPN. For internal work, testing runs on a node inside your network that you control; it connects outbound only and any credentials you grant stay on it. Testing is confined to the approved targets by the engine itself, and you have a named contact throughout.

Externalno access required
Internalon-premise node · outbound-only · your credentials stay local
03Verify

Every candidate finding is checked by a person.

Automated tooling produces candidates, not conclusions. We confirm or drop each one by hand, grade it by the evidence behind it, and rank what remains by real-world exploitation (CISA KEV, EPSS) rather than by CVSS score alone. Version guesses are never forwarded as facts.

GradesActionable · Potential · Validated-safe
Rankingwhat attackers are using now, first
04Report

A short list of what matters, with the fix.

You get an executive summary for the business and a technical section for whoever will do the work: each material finding with its evidence, its grade, why it matters in your context, and the fix in plain language. Then we walk your team through it on a call. See a sample report →

05Remediate

We stay available while the fixes land.

Questions from your engineers during remediation are part of the engagement, not an extra. If a fix is not practical, we help you find a compensating control and say so in the re-test.

06Re-test

We confirm the issues are actually closed.

One re-test of the reported findings is included in every cyber review. Repeat it annually or quarterly and this becomes the next cycle: we track what is new, what got fixed and what is still open between rounds, and flag anything material as soon as we see it.

Every reviewone re-test included
Cadenceannual or quarterly cycles · change tracking
ServicesServices →

Practicalities

What we need. What you get back.

AFrom you

Before we start.

  • ✓ The target list — domains, IP ranges or hostnames for external work; network ranges and any systems to exclude for internal work.
  • ✓ A technical contact we can reach during the testing window, and who to call if something looks wrong.
  • ✓ Testing windows if timing matters (change freezes, business hours, maintenance windows).
  • ✓ For internal work only: a host or VM for the node (one static binary, outbound HTTPS) and any accounts you want authenticated checks to use.
  • ✓ Approval of the written scope. That is the only paperwork; we sign your NDA if you have one.
BFrom us

What is in the deliverable.

  • ✓ Executive summary — posture in one page, the material risks, what to do first.
  • ✓ Ranked findings — each with evidence, grade, business context and a plain-language fix.
  • ✓ Verified-safe list — what the tooling flagged that we checked and ruled out, so nobody chases ghosts.
  • ✓ Findings walkthrough with your team, and availability during remediation.
  • ✓ Re-test report confirming what is closed and what remains.
  • ✓ Formats: PDF for the report; findings as CSV or JSON on request for your ticketing.

Glossary

The words in the report.

TermWhat it means here
ActionableA finding we reproduced with evidence. It is real, it is reachable, and it has a fix. These are the items in the summary.
PotentialSomething the tooling or version information suggests but we could not confirm without a change on your side (a credential, a maintenance window). Listed separately, never counted as a breach.
Validated-safeA candidate the tooling raised that we checked and ruled out. Reported so you can see what was tested, and so you do not pay someone else to chase it.
External reviewTesting from the internet, as an attacker would see you. Needs no access to your network.
Internal reviewTesting from inside your network, run on a node you host. Finds what an attacker with a foothold, or a malicious insider, could reach.
Credentialed checkAn authenticated look at a host (SSH / WinRM) for patch level and configuration. Only ever from your node, with accounts you provide.
CISA KEVThe US CISA catalogue of vulnerabilities known to be exploited in the wild. Anything on it goes to the top of your list.
EPSSA daily probability that a given vulnerability will be exploited in the next 30 days. We use it to rank, alongside KEV and your context.
CVSSThe standard severity score. Useful, but it says nothing about whether anyone is actually exploiting the issue, which is why it does not drive our ranking on its own.
Scope gateThe engine refuses to test any address not on the approved list. It is how the written scope is enforced technically, not just contractually.
Re-testA second pass over the reported findings after your fixes, to confirm they are closed. Included in every cyber review.

Frequently asked

Before you book.

Do I need to install anything or open firewall ports?

Not for an external review. For internal work, one node inside your network: a single static binary that connects outbound over HTTPS. No inbound ports, no VPN, and nothing can connect into your network from outside.

How long does a review take?

Typically one to three weeks from start to report for a cyber review, depending on scope; an ITGC audit is scoped to the domains and period in question. The scoping call and written scope come first; we give you the timeline with the quote.

Will testing disrupt production?

Testing is non-destructive by default and confined to the approved scope. Anything with a realistic chance of impact is agreed in the rules of engagement first, with a window and a contact. You can pause testing at any time with one message.

What do you keep afterwards, and for how long?

The findings, the report and the evidence behind each reported item, so the re-test has something to compare against. No raw scan output and no credentials. Retention is agreed in the scope; the default is deletion after the re-test, with a copy left with you. Details on Security & data handling.

Is this a penetration test?

It is a verified vulnerability assessment with manual validation of every finding. If you need a full adversary-simulation penetration test for a specific compliance requirement, say so on the scoping call and we will tell you honestly whether we are the right fit.

Can I see what a report looks like first?

Yes — the sample report shows the structure, the grading and the level of detail. And the free exposure review gives you a real, if small, taste of the output before you commit to anything.

Ready when you are

Start with the call. Or start with zero access.

Book the scoping call and get a written scope and quote, or let us look from the outside first with a free exposure review.

Talk to Cyentrix → Free exposure review