Blackbourne Worldwide BlackbourneWorldwide

Home / How we work

Methodology

Authorised, scoped and evidenced.

Offensive security only works if it is legitimate. Every engagement begins with written authorisation and a defined boundary, and ends with evidence your team and your auditors can rely on.

Authorisation

Signed scope, targets, exclusions, stop conditions and emergency contacts. Nothing is tested before this exists.

Research

Open-source and technical research on the agreed targets. Attack paths are built specifically for your environment.

Execution

Testing runs to scope, with findings and evidence captured as they are produced and safe-stop rules observed.

Investigation

Every attack is followed by a full-scale cyber-forensic investigation, with malware sent to R&D.

Hardening

The holistic understanding of the threat and malware drives infrastructure hardening and advanced threat detection.

Before we start

What has to be true.

  • Written authorisation from someone with the authority to grant it, naming the scope.
  • A named emergency contact reachable during testing, including out of hours.
  • Stop conditions agreed in advance — the findings that end the engagement early.
  • Explicit exclusions for systems, third parties and data that must not be touched.
  • A data handling agreement covering anything captured during the work.
  • Agreed notification for critical findings, so you are not reading them in a report weeks later.

Third parties are never in scope by default. Cloud providers, SaaS vendors, suppliers and your own customers each have their own authorisation requirements. If a test would touch a third party, it is either excluded or we tell you what permission you need to obtain first.

We will decline work. If a request would require testing without authorisation, targeting individuals outside the agreed population, or producing work intended to harm a person or organisation, we decline it. That is not a formality — it is the line that separates this work from the thing it imitates.

Evidence

What the engagement leaves behind.

DeliverableContents
Findings reportOrdered by what an attacker would do next, with reproduction steps and evidence.
Forensic reportWho, what, when, why and how — with a reconstructed timeline.
Malware analysisCapability, persistence, indicators and derived detection logic.
Hardening planPrioritised infrastructure and configuration changes.
Detection packageRules and hunting queries built from observed behaviour.
WalkthroughA session with your engineers, not a PDF handover.
RetestVerification that remediation actually closed the path.

Start the scoping conversation.

Tell us what you want tested and what must not be touched. We will produce a scope document and authorisation pack for your legal team to review.