The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Security Office
A testing team on hand all year, without a new contract for every test.
Instead of opening a new negotiation for every new system, you contract a volume of testing hours and draw on them when needed: internal testing, external testing, web applications, mobile apps, and retesting after fixes. It is the format for teams that ship often and cannot wait for the next procurement cycle to find out whether what went live can withstand attack.
No test starts without the step that protects both sides: written scope, defined windows, emergency contacts, and formal authorization. Then come the execution, the technical report with every finding, how to reproduce it, and how to fix it, and the retest, which confirms item by item that the gap is closed. Planning is reviewed with you every month, along with hour usage.
On your side, we need formal authorization from whoever owns each environment, contacts who respond if anything goes outside the window, and someone to prioritize with us at the monthly meeting. Hours left over at the end of the period are not lost: they carry over into the renewal.
The options change how you draw on the hours. With a calendar set at the start, the plan is locked from day one, which better fits audit requirements. On demand, the hours stay available and prioritization is revisited every month, at the pace of teams that ship often. The term, twelve to twenty-four months, sets how much room you have to reschedule without losing hours.
The stages and deliverables below describe the Calendar agreed at the start · 12 months modality. The other modalities appear when you request the proposal.
Planning and authorisation
We agree the scope in writing and set the windows, the emergency contacts and the formal authorisations. No test starts without that.
Execution
We run the test cycle within the authorized window and scope, starting with what usually breaks first. Every finding is recorded with the evidence and the step-by-step needed to reproduce it later.
Report
We consolidate the findings into a report where every item comes with severity, evidence and the path to fix it. We write to be read by the people who will act, not to fatten pages.
Retest
Once your team has fixed things, we come back and confirm item by item that the gap closed.
Presentation
A meeting with leadership translating the technical result into business risk and investment decisions. We arrive with the answers to the questions the board always asks: what to attack first, how much effort it takes and what happens if nothing is done.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.