FD.Solutions

Methodology

Standards a reviewer can check your report against.

We test against established, recognized standards — which is what makes results defensible when a reviewer asks how the assessment was conducted.

StandardApplied to
OWASP WSTGWeb application testing
OWASP MASTGMobile application testing
OWASP API Security Top 10API and backend testing
OWASP ASVSSecure development requirements
PTESOverall engagement structure
NIST SP 800-115Technical assessment methodology
CIS ControlsInfrastructure hardening benchmarks
PCI DSS Req. 11.4Payment environment testing and segmentation

Findings are scored using CVSS v3.1, with severity adjusted for real-world exploitability in your environment rather than reported as raw base scores.

How an engagement works

Seven steps from the first call to the clean report you can submit.

  1. 1

    Scoping call

    We establish what needs testing, what the report is for, and who will review it. The end requirement shapes the entire engagement.

  2. 2

    Authorization and rules of engagement

    Written scope, signed testing authorization, agreed testing windows, emergency contacts. Nothing begins without documented permission.

  3. 3

    Reconnaissance and mapping

    We map the full attack surface — often finding exposed services the client didn't know were reachable.

  4. 4

    Testing

    Automated coverage for breadth, manual testing for depth. Critical findings are reported immediately rather than held for the final report.

  5. 5

    Reporting

    Full documentation within ⟨5⟩ business days, followed by a walkthrough call with your technical team.

  6. 6

    Remediation window

    Your team fixes; we support. Direct access to the tester who found each issue.

  7. 7

    Retest and final report

    Verification of every fix, and the clean report you can submit.

What you receive

Every assessment delivers a complete evidence package, not a scanner export with a logo on it.

  1. Executive summary

    Overall risk posture in plain language for the person signing off, with an explicit statement of outstanding findings by severity.

  2. Technical findings report

    Each finding with CVSS v3.1 score, business impact, affected components, proof-of-concept evidence, and reproduction steps.

  3. Remediation plan

    Specific, actionable guidance ranked by priority, written for the developers implementing it.

  4. Scope and methodology statement

    Every tested URL, IP, endpoint, and application build with version numbers; testing dates; standards followed; tools used.

  5. Tester credentials and independence statement

    Certifications held and a signed declaration of independence. Compliance reviewers check this first.

  6. Retest report

    Verification that each finding is closed, with a clear final position.

  7. Signed and stamped attestation letter

    On company letterhead, in the format banks and PSPs expect.

Reports delivered in English and Arabic on request.

Find out what's exposed — before someone else does.

Tell us what you need tested and who's asking for the report. A short scoping call is usually enough to give you a clear scope, timeline, and fixed price.

Request a Scoping Call