Good preparation ensures that the pentest runs efficiently and that critical findings can be addressed immediately. Preparation has two sides: technical preparation of your environment and organizational preparation within your team.
Technical preparation
- Test environment up-to-date and representative. Ensure the pentest environment contains the latest code and configurations. Ideally this is an acceptance or test environment. If the environment is not an exact copy of the production environment, it is essential that test data is present so that all functionalities can be evaluated.
- Verify functionality. Confirm that all functionalities and components within the application work as intended. Inform the pentesters in advance if certain features are not working in the test environment. Populate the test environment with anonymized or dummy data so that all functionality can be exercised during the pentest.
- Create backups. Since data can be modified or deleted during testing, it is crucial to create a full backup of your test environment before the pentest starts.
- Whitelist IP addresses. Notify your hosting provider and ensure DongIT's IP addresses are whitelisted for firewalls, IDS, IPS and rate-limiting systems during the test period. See the FAQ on why IP whitelisting is needed.
- Adjust SMTP settings. Configure SMTP settings so our pentesters can view all email messages sent by your application. See the FAQ on SMTP configuration for a pentest.
- Provide test information. Depending on the type of pentest, specific information is needed, such as test accounts, API documentation, architecture diagrams or source code. See the FAQ on what information you provide.
Organizational preparation
- Designate a contact person. Assign a primary contact person who is available by phone during the pentest period. This person receives direct notifications of critical findings and serves as point of contact for our pentesters.
- Determine decision-making authority. Determine who in your organization has authority to take immediate action if a critical vulnerability is discovered. For example: temporarily disabling a feature, taking a service offline or activating incident response.
- Incident response plan ready. Ensure your incident response plan is known and up-to-date with all relevant team members. This helps to respond quickly and in a coordinated way to critical findings.
- Team communication. Inform involved teams (IT, developers, security, management) that a pentest is taking place, so they are not surprised by elevated logging or test requests.
What happens with critical findings
When our pentesters discover a critical vulnerability, it is published within hours on our Security Reporter platform, followed by a phone call to your designated contact person. This way you can take immediate action without waiting for the final report. See the FAQ on communication of critical vulnerabilities.
What DongIT does to prepare
On our side, the pentest team also prepares:
- Kick-off meeting. Discussing scope, contact persons, communication channels and expectations.
- Scope verification. Confirming in-scope and out-of-scope components, URLs, endpoints and user roles.
- Tooling and methodology. Preparing test tooling tailored to your tech stack and compliance requirements.
- Whitelisting instructions. Providing our IP addresses and test user-agents for your whitelisting configuration.
Questions about preparation or scope? Contact us for a complimentary scoping conversation, or view our pentest packages.
Nederlands