Division 01 / Understand the exposure

Know what needs protecting. And why.

Security audits, penetration testing and security assessment. Start with the system, the concern and the decision you need to make.

Choose the question before the method.

A security concern is difficult to act on when the boundaries are unclear. The first task is to distinguish what is known, what needs checking and what testing is actually authorized.

Compare security methods and the questions they help frame
MethodQuestion and scope
Security audit

Do the agreed requirements or controls hold up?

A review against agreed requirements or controls. Useful when you need to understand the evidence behind an existing security position.

Penetration testing

Where might an authorized system be exploitable?

An agreed attempt to identify exploitable weaknesses in specifically authorized systems. Scope, access and testing limits must be settled before activity begins.

Security assessment

What needs investigating before the next decision?

A broader examination of a defined security concern. Useful when you first need to decide what to investigate, change or test in greater depth.

02 / Define the engagement
Proposed scope · Awaiting business confirmation

Make the deliverables part of the conversation.

A defined boundary

Proposed scope: the assets, questions, exclusions, permissions and conditions that govern the work.

Findings with context

Proposed output: observed issues, supporting evidence, impact and limitations, with priorities explained rather than presented as a score alone.

A next-action record

Proposed output: remediation options and any agreed follow-up checks. Retesting is a separate scope decision.

These are proposed scoping topics, not a fixed package or a delivery promise. Methods, outputs, responsibilities, timing and fees need to be confirmed before an engagement.

03 / A useful first message

Start with what you know.

  1. What system or security concern do you want to understand?
  2. Do you own the system, or can you obtain written testing authorization?
  3. Is a particular release, review or business decision driving the request?

Keep the first message high-level. Do not include passwords, access tokens or confidential records.

04 / Questions worth asking

A few things to know.

Do I need a penetration test or a security audit?

It depends on the question. An audit examines agreed requirements or controls; penetration testing investigates exploitable weaknesses within an authorized scope. Describe the decision you need to make before choosing the method.

Can testing begin from a website address alone?

No. A public address does not establish permission. Asset ownership, written authorization, scope and testing conditions need to be agreed first.

Does an assessment prove a system is secure?

No. An assessment provides evidence within its scope and at a particular time. Its limits, exclusions and remaining uncertainty should be explicit.

What should I send in the first inquiry?

Send a high-level description of the system and your concern. Do not send passwords, access tokens, exploit code or confidential technical material through the initial contact form.

Is this the right route to report a NovaGrex vulnerability?

Use the Security / Responsible Disclosure page for a concern about NovaGrex itself. This division inquiry is for discussing a potential security engagement.

The next conversation

Bring the problem into focus.

An outline is enough to begin. Tell us the situation and the decision you need to make.

Discuss a security concern