Before testing begins.
WHAT TO PREPARE
Authorisation, signed Scope confirmed with the tester Contacts on both sides Notification to anyone who needs to know Backups verified Monitoring aware
WHY BACKUPS
Testing occasionally causes problems and recovery must be possible.
WHAT TO VERIFY
That backups exist and can be restored.
WHY VERIFY
Untested backups fail when needed.
WHAT TO NOTIFY
Your hosting or cloud provider, where required Your monitoring or security provider Internal teams who would otherwise respond
WHY INTERNAL TEAMS
Testing that triggers a genuine incident response wastes everyone's time, unless that is the intention.
WHAT TO ESTABLISH
Whether the response teams should be informed.
WHY IT IS A DECISION
Informing them tests the systems; not informing them tests the response.
WHAT TO AGREE
Which you are testing.
WHAT TO PROVIDE THE TESTER
Scope details Access credentials, where agreed Documentation, where agreed Contact for problems
WHAT TO ESTABLISH ABOUT CREDENTIALS
That test accounts are used, not real ones.
WHY
It limits what is reached and it allows removal afterwards.
WHAT TO PREPARE INTERNALLY
Capacity to act on findings.
WHY
Assessment producing findings nobody can address is expenditure without benefit.
WHAT TO ESTABLISH
Who will own remediation.
WHAT TO AVOID
Making changes during testing.
WHY
It invalidates findings and confuses results.
WHAT TO RECORD
The state of systems at the time of testing.