Preparing for Security (Pen) Testing Engagements

Last updated: October 8, 2025

When scheduling a security testing engagement, there are several key pieces of information and preparations needed to ensure a smooth process.

What you need for a Pen-Test with Mycroft

  1. Included in your subscription

  2. Preferred pen-test dates

  3. Signed Rules of Engagement Letter (ROE)

If a pen-test is not included in your subscription, reach out to Mycroft for more information.

Download our Rules of Engagement Template here

How soon can I get a pen-test with Mycroft?

Reach out to Mycroft for the next available pen-test date, or to inquire if your preferred date is available. As they are subject to availability from our security analysts, we cannot guarantee dates and recommend making arrangements in advance. Pen-test dates are secured after the Rules of Engagement letter is signed.

If your preferred date is not available, or you would like a pen-test sooner, we can keep you informed of dates that are tentatively booked (pending signed ROE), or of last minute changes/cancellations.

Do I need to be available during testing?

No, you don't need to be present during the actual testing. As long as the ROE is signed beforehand and the testing team has the necessary accounts and access, the engagement can proceed without your direct involvement.

Required Information for Rules of Engagement

Before testing begins, you'll need to provide the following details:

Client Information

  • Client contact email

  • Client contact phone number

  • Primary contact name and title

Targets in Scope

  • Asset Name: Description of what will be tested (e.g., "Client Website")

  • Asset Details: URLs or specific endpoints

  • IP Ranges: Leave blank if testing the entire site

Test Credentials

  • Username/password or authentication method (e.g., "sign in with Google")

  • Can be shared via secure methods like 1Password or SharePoint

  • For GitHub authentication, the account should be activated with full paid user features

Timeline and Schedule

  • Engagement start date

  • Engagement end date

  • Testing window preferences (days/hours)

Test Environment Recommendations

It's strongly recommended to set up a test/development environment for the engagement rather than using production systems. This prevents any potentially destructive actions from affecting live customers. The test environment should be available for the entire engagement window.

Scope and Exclusions

Testing typically covers both the dashboard and API that users would normally access after logging in. You can specify any targets out of scope, such as:

  • Features currently under development

  • Known vulnerable components that aren't ready for testing

  • Areas that will change soon

Most customers don't have exclusions, but if you do, clearly specify them in your requirements.

API Documentation

If available, providing API specifications or OpenAPI documentation can help achieve better test coverage by ensuring no endpoints are missed during testing.