Skip to content

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Editorial team 2 min read

Rules of engagement exist to make testing safe, lawful and useful. Write them down before the first packet.

What belongs in the document

Scope. Named systems, address ranges, domains and accounts — and explicitly what is out of scope. Third-party hosted systems need the provider's authorisation too; your contract with a SaaS vendor rarely grants you permission to test their platform.

Authorisation. Signed by somebody who actually owns the systems. This is the clause that distinguishes testing from an offence under computer misuse law in most jurisdictions.

Timing. Windows for noisy activity, change freezes to respect, and whether the blue team is told. "Nobody told operations" is the most common cause of an unnecessary incident.

Technique limits. Denial of service, social engineering, physical access, testing in production, and what happens on finding live customer data. Say what is permitted rather than listing what is not.

Data handling. What may be captured, where it is stored, how long it is kept and how it is destroyed. A tester's evidence archive is a concentrated copy of your worst exposures.

Contacts and escalation. Who to call on discovering a critical issue or evidence of a prior compromise, and the number that works at 3am.

Stop conditions

Agree in advance what halts the engagement: a production outage, discovery of an active intruder, or anything suggesting the test has strayed outside scope. A test that quietly continues past a stop condition becomes somebody else's incident.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025

Cyber security Guide · 2 min

The OWASP Web Security Testing Guide

A shared checklist for testing web applications, and how to use it without turning testing into box-ticking.

Cyber security 2 min read 21 May 2025