Skip to content
SecuriFii

Testing

Four decisions nobody wants to make at 2am during a test

Most of a rules-of-engagement document can be filled in by whoever schedules the work. Four questions cannot, because each one is a decision about what you are willing to have happen, and each gets asked at the worst possible moment if it was left blank.

Facts checked2026-09-11

What must the rules of engagement settle?

What happens if the tester finds evidence of an existing compromise? This is the one that actually occurs and the one most often unaddressed. Testing stops or continues, somebody specific is called, and the call happens at whatever hour it happens — decide the path and name the person now, because the alternative is improvising incident response while a contractor waits.

What does the tester do on reaching live customer data? Access it to prove the finding, or stop at the boundary and report the reachability? Both are defensible, the answers have different privacy consequences, and it is your call rather than theirs.

Which techniques are excluded, and out of which hours? Denial of service, social engineering and anything destructive are the usual exclusions, and an operational system is often better tested outside business hours — which has its own consequence, because the people who would notice a genuine incident are asleep.

And who can authorise all of it? Signed by somebody with actual authority over the assets, including anything hosted by a provider whose terms require notification. A test running on unclear authority is the one problem in this list that can become a legal question rather than an operational one.

The bottom line

Settle the compromise-discovery path before anything else. It is the question people leave blank, the one most likely to be needed, and the only one on this list that asks you to improvise incident response under time pressure.

Related insights