Preparing for Security (Pen) Testing Engagements
Last updated: October 8, 2025
When scheduling a security testing engagement, there are several key pieces of information and preparations needed to ensure a smooth process.
What you need for a Pen-Test with Mycroft
Included in your subscription
Preferred pen-test dates
Signed Rules of Engagement Letter (ROE)
If a pen-test is not included in your subscription, reach out to Mycroft for more information.
How soon can I get a pen-test with Mycroft?
Reach out to Mycroft for the next available pen-test date, or to inquire if your preferred date is available. As they are subject to availability from our security analysts, we cannot guarantee dates and recommend making arrangements in advance. Pen-test dates are secured after the Rules of Engagement letter is signed.
If your preferred date is not available, or you would like a pen-test sooner, we can keep you informed of dates that are tentatively booked (pending signed ROE), or of last minute changes/cancellations.
Do I need to be available during testing?
No, you don't need to be present during the actual testing. As long as the ROE is signed beforehand and the testing team has the necessary accounts and access, the engagement can proceed without your direct involvement.
Required Information for Rules of Engagement
Before testing begins, you'll need to provide the following details:
Client Information
Client contact email
Client contact phone number
Primary contact name and title
Targets in Scope
Asset Name: Description of what will be tested (e.g., "Client Website")
Asset Details: URLs or specific endpoints
IP Ranges: Leave blank if testing the entire site
Test Credentials
Username/password or authentication method (e.g., "sign in with Google")
Can be shared via secure methods like 1Password or SharePoint
For GitHub authentication, the account should be activated with full paid user features
Timeline and Schedule
Engagement start date
Engagement end date
Testing window preferences (days/hours)
Test Environment Recommendations
It's strongly recommended to set up a test/development environment for the engagement rather than using production systems. This prevents any potentially destructive actions from affecting live customers. The test environment should be available for the entire engagement window.
Scope and Exclusions
Testing typically covers both the dashboard and API that users would normally access after logging in. You can specify any targets out of scope, such as:
Features currently under development
Known vulnerable components that aren't ready for testing
Areas that will change soon
Most customers don't have exclusions, but if you do, clearly specify them in your requirements.
API Documentation
If available, providing API specifications or OpenAPI documentation can help achieve better test coverage by ensuring no endpoints are missed during testing.