How Snipeyes runs a penetration test, and what you receive at the end
Many penetration test reports are hard for a board to use. They run to dozens of pages of technical codes with no explanation of what the problems mean for the business. This page explains how we run a test, from the first call to the retest, and what each part of your organization receives.
Where CREST fits
Snipeyes is accredited by CREST, the international body that accredits security testing companies and certifies individual testers. CREST does not prescribe how to test. It checks that an accredited company has a documented, quality-controlled approach and follows it.
The approach below is our own. It draws on public standards: the OWASP Web Security Testing Guide (WSTG) and Application Security Verification Standard (ASVS), PTES, NIST SP 800-115 and MITRE ATT&CK, a public catalog of real attacker techniques. Our testers hold CREST certifications.
From first call to retest
- Scoping and rules of engagement. In a 90-minute workshop we agree the objectives, the systems that are off limits, which systems matter most to the business and the attackers you are most likely to face. The NDA is signed at this stage. Careful scoping is what prevents surprise outages.
- Reconnaissance. We map what an outsider can learn about you: public information, systems reachable from the internet and the entry points they expose.
- Finding weaknesses. Tools such as Burp Suite and Nessus do the broad sweep. Testers then work through OWASP WSTG and ASVS by hand and confirm each result before it goes into the report.
- Exploitation with a goal. We try to reach agreed objectives, such as customer personal data, another user’s account or the ability to run our own code on a server. Every successful chain of steps is documented from start to finish.
- Moving further in, and checking detection. Where it is in scope, we try to move between systems and stay hidden. We also check whether your security monitoring team notices us.
- Reporting, briefing and retest. You receive the report and a live debrief. Once you have fixed the findings, we retest within 30 days at no extra cost to confirm the fixes hold.
What you receive
The board and executives get a two-page summary. It includes a heat map (a chart of risks by likelihood and impact), the business impact in financial and reputational terms, and the investments we recommend. We write it so your chief executive can forward it without an explanation.
Your engineers get the technical findings. Each comes with a proof of concept (a safe demonstration that the weakness is real) and redacted evidence such as screenshots and Burp logs. It also carries a CVSS 3.1 score and an OWASP Risk Rating, plus fix guidance ordered by how easily each weakness can be exploited.
Your auditors and compliance team get a map that links each finding to the controls it affects. For example, an IDOR (a flaw where changing an ID in a request reveals someone else’s data) maps to ISO 27001 A.8.26, SOC 2 CC6.1 and PCI DSS 6.2.4. We map to ISO 27001, SOC 2, PCI DSS and GDPR as your reporting requires.
The appendix records the scope, the rules of engagement, our testing approach, the anonymized certifications of the testers (CREST CRT and CCT), the tools used and the retest results. The full report arrives within 10 business days of testing.