Engagement process

How I work

I use a transparent process from the initial consultation to actionable results, with agreed communication and secure handling of confidential information throughout.

1. Initial consultation and objectives

Abstract illustration for initial discussion and goal clarification

During the initial consultation, we clarify your objectives, constraints and expectations: Which systems, applications or teams are involved? Which risks concern you? What outcome should the engagement deliver?

2. Needs assessment and proposal

Abstract illustration for needs analysis and technical proposal

Based on these objectives, I assess which core service is appropriate—a penetration test for web applications and APIs, secure development and security review support, or developer security training—and recommend a suitable approach.

3. Proposal, scope and authorisation

Abstract illustration for proposal, scope and authorisation

I prepare a transparent proposal with a clearly defined scope, methodology, schedule and responsibilities. Once you have approved it in writing—and, for technical assessments, issued a permission to test—we agree on access, contacts and dates.

The scope also covers testing boundaries, permitted methods, time windows, affected systems, contacts, escalation channels and the handling of production data. Access credentials, documents and test data are transferred through agreed secure channels. Sensitive information is used only for the engagement and only to the extent necessary.

4. Delivery and ongoing coordination

Abstract illustration for delivery and ongoing coordination

I deliver the agreed service, whether it is a technical assessment, consulting engagement or training. I report important security findings early, coordinate relevant interim results with you and adjust the focus where necessary.

For critical findings, we agree on a communication channel in advance so that the relevant contacts can respond quickly. I document results reproducibly, avoid unnecessary data exposure and work within the agreed permission to test.

5. Results, report and recommendations

Abstract illustration for results, report and recommendations

You receive clear, comprehensible deliverables: technical reports, management summaries, prioritised review recommendations or training materials. Findings are prepared so that your teams can use them directly.

For technical assessments, the report typically includes a management summary, prioritised findings, technical reproduction steps, risk and impact ratings, and specific recommendations. Delivery takes place through an agreed secure channel. Confidential details, credentials and personal information are documented only where necessary for assessment and remediation.

6. Review, support and retest

Abstract illustration for review, support and retest

In a review meeting, we address open questions and prioritise the next steps. If required, I can continue to support your team—for example with remediation, SDLC or DevSecOps processes, or recurring workshops.

Once findings have been remediated, we can arrange a focused retest. I verify whether the agreed measures are effective and whether the changes have introduced new risks.

Next steps

If you have questions about the process or would like to discuss a specific project, please get in touch. I usually respond within one to two business days.

Discuss your project