Process
Engagement Management
Security Penetration Testing is no longer a niche activity; it is now a cornerstone in every enterprise organisation’s security programme. With the growth of the industry new trends have emerged, with more focus on automation and harnessing technology to deliver project management and reporting.
Process Index
Select a stage to read more detail.
Engagement Flow
A clear, deconflicted path from discovery to delivery with defined checkpoints and outputs.
Plan & Prepare
Client & Contractor Onboarding
Testing Window
Reporting & QA
Plan and Prepare
Once we engage with a client our first step is a call to understand what your requirements are. For very small engagements these requirements can be gathered via a questionnaire if that suits you best. We can engage in varying project types and lengths:
Project Based
Fixed Man Day Project: Penetration Test & Red Team.
We sit with you to understand the scope of the work and your requirements; the targets of the testing, the urgency, and the reason for the testing. We then furnish you with a proposal based on our understanding of your requirements, outlining our methodologies, approach and the consultants we want to bring onto the project.
Service Line Agreement (SLA)
3, 6, 12 Contractor Placement.
If you need long-term, continuous presence in your organisation to augment existing testing capability, deliver programme development, conduct custom research, or engage in a long-term advanced intrusion test, we will understand your requirements, skillsets sought, and budget. We present candidate resumes from Atlan’s pool of consultants, vetted, NDA-signed, technically interviewed and referenced. During delivery we manage timesheets, augment capability for illness or change of requirements, and provide technical management and support.
PTaaS or RTaaS
Penetration Testing-as-a-Service and Red Team-as-a-Service.
We engage with you to understand your requirements, skillsets sought, and experience with certain technologies, then present a solution where you block-buy man days per month (minimum of 10 man days per month, minimum three months commitment). We provide consultant resumes and can augment with automation or custom tooling for daily, weekly or monthly scans, with PDF reports or integration into your project management software such as JIRA.
Client and Contractor Onboarding
Contractor onboarding
Atlan maintains a pool of consultants all with a minimum of 5 years testing experience, generally around ten. All contractors sign an NDA and are briefed on our security policies before we engage. We provide our consultants with:
- Atlan corporate email account
- Access to Atlan digital communication platform and shared drives on Atlan’s internal systems
- Access to VPN and tooling where necessary on our cloud-based infrastructure
- Reporting platform, reporting formats and vulnerability databases
We do not rely on automated platforms to manage our consultants, and provide technical oversight and project management throughout every project. If a scoped consultant is no longer available, we present another equally experienced consultant for client approval before continuing.
Client onboarding
Atlan will comply with all client’s reasonable demands, present our data handling policy, sign Non-Disclosure Agreements, and provide corporate and accounting information where necessary.
You deal with people rather than automated systems, and we have our internal team on hand to manage challenges, respond to queries and provide documentation promptly for your legal and compliance teams.
Testing Window and Engagement Management
Penetration Testing: Kick Off → Testing → Weekly Updates → Debrief.
1. Kick Off
Atlan’s internal team and technical manager bring the consultants onto a kick off call to introduce the testing team and client over video conference, aligning expectations and raising any risks or concerns.
2. Testing
Throughout testing Atlan technically manages the project, providing technical leadership, project management and remaining on standby. Where critical issues or risks are identified we engage with the client immediately.
3. Red Team & PTaaS/RTaaS weekly update
For long-term phases Atlan hosts weekly washup calls covering testing activities and milestones, and to take additional steer. Updates are provided over video conference with a presentation of milestones and highlighted risks.
4. Project Finish Debrief
Once the report is delivered, Atlan’s internal team and consultants host a project debrief call to address any testing limitations and questions.
Reporting and Quality Assurance
Project Based Reporting
Where Atlan has been engaged for a single project, whether systems Penetration Testing or Red Teaming, the final deliverable will be a PDF report. Once consultants have written their findings and submitted evidence to Atlan’s report format, our comprehensive multi-stage technical QA process begins:
Initial technical QA
A senior reviewer validates the evidence, severity, reproduction steps, and remediation guidance.
Consultant revisions
The delivery consultant addresses review comments and completes any additional validation required.
Final revisions
Findings, risk ratings, and the executive summary receive a final consistency and quality check.
Release
The approved report is issued securely, followed by a client walkthrough and remediation discussion.
Where there is a requirement to use the report format of an end client or reseller partner, our team will adapt our reporting process to present findings in this format. Our consultants are freelance testers experienced with multiple report formats from varied consultancies and international clients.
PTaaS and RTaaS
Where we deliver a continuous service based on 20 man days per month we can provide issues and vulnerabilities identified in the following formats:
- Monthly PDF Reports
- We can populate internal Jira or similar ticketing systems with findings, or develop plugins from our reporting system to populate findings in your own.
- Excel findings, issues identified on a weekly or monthly basis in excel format outlining all risks, according to our internal grading system or to match yours.
Enquiries
Send us a brief outline of what you are looking for and we will respond directly.
Contact Us
How can we help?
Whether you represent a corporate, a consultancy, a government or an MSSP, we’d love to hear from you. To discover just how our offensive security contractors could help, get in touch.
