Testing
Four decisions nobody wants to make at 2am during a test
Most of a rules-of-engagement document can be filled in by whoever schedules the work. Four questions cannot, because each one is a decision about what you are willing to have happen, and each gets asked at the worst possible moment if it was left blank.
Facts checked — 2026-09-11
What must the rules of engagement settle?
What happens if the tester finds evidence of an existing compromise? This is the one that actually occurs and the one most often unaddressed. Testing stops or continues, somebody specific is called, and the call happens at whatever hour it happens — decide the path and name the person now, because the alternative is improvising incident response while a contractor waits.
What does the tester do on reaching live customer data? Access it to prove the finding, or stop at the boundary and report the reachability? Both are defensible, the answers have different privacy consequences, and it is your call rather than theirs.
Which techniques are excluded, and out of which hours? Denial of service, social engineering and anything destructive are the usual exclusions, and an operational system is often better tested outside business hours — which has its own consequence, because the people who would notice a genuine incident are asleep.
And who can authorise all of it? Signed by somebody with actual authority over the assets, including anything hosted by a provider whose terms require notification. A test running on unclear authority is the one problem in this list that can become a legal question rather than an operational one.
The bottom line
Settle the compromise-discovery path before anything else. It is the question people leave blank, the one most likely to be needed, and the only one on this list that asks you to improvise incident response under time pressure.
Related services
Vulnerability Assessment and Penetration Testing (VAPT)
Find what an attacker would find, ranked by what it would actually cost you — and get a report your auditor and your engineers can both use.
Related insights
Technical testing
The OWASP Testing Guide, and how to tell a real penetration test from a scan
Two tests can cost the same and cover entirely different ground. The methodology is how you tell, and it is checkable before you pay.
Technical testing
NIST SP 800-115: the four phases, and the one that is not a phase
The four-phase shape behind most credible test methodologies — and the phase that is not fourth at all.
Testing
What a CVSS score does and does not tell you about your risk
A shared scale for technical severity — deliberately context-free, which is exactly why it is not your priority order.