forumNew topic

How do you define the scope of written authorization for a penetration test, and what should be in the document?

NNihal T***Veteran
Job title
CPA
Joined
Jul 2023
Message
129
#1

We are a 14-person software company in the fintech space providing B2B invoicing and reconciliation software to enterprise clients. Two major banks and a retail giant that are about to join our portfolio have made an independent firm's penetration test report mandatory before integration. Contracts worth a total of 600,000 TL annually are on the table.

Before we start working with the cybersecurity firm we choose, we need to draw up a written authorization and scoping document. However, our cloud infrastructure includes shared servers, third-party payment gateways, and live production databases that cannot tolerate any downtime whatsoever. We are worried that an erroneous scan might crash our servers or cross legal boundaries.

What systems, test types, time windows, and legal protection clauses must absolutely be included in this written authorization and scoping form? What conditions should we put in the contract to ensure operational safety?

AAslı K***ExpertCommunity member
Joined
Oct 2022
Message
91
Most Helpful#2

Short answer: A written penetration testing authorization document acts as a legal shield that protects the testing team from allegations of cybercrime while protecting the client from uncontrolled outages and scope creep. It must explicitly list target IPs and domains, excluded systems, permitted testing methodologies, and an emergency stop protocol.

Essential elements that must be in the scoping document: 1) A complete inventory of target assets; static IP addresses, API endpoints, and subdomains to be included in the test must be written out individually, not as ranges. 2) A list of forbidden tests; denial-of-service attacks on production, social engineering, and destructive database write operations must be explicitly ruled out of scope. 3) Testing time windows; low-traffic night hours or weekend slots must be strictly defined.

If you're using cloud infrastructure, review your provider's penetration testing policy beforehand. While most public cloud providers allow tests that mimic standard user traffic directly, they prohibit excessive resource consumption that affects shared infrastructure. A commitment stating that the testing firm will fully comply with cloud provider rules should be added to the document.

Finally, establish a two-way emergency communication mechanism. The operational contacts authorized to halt the test immediately with a single phone call or encrypted message the moment an unexpected outage, lockup, or data anomaly is detected must be signed into the document with their titles and phone numbers.

PPolat G***Member
Job title
Chief Technology Officer
Sector
Printing
Organization type
8-person team
Joined
Aug 2023
Message
275
#3

Definitely include a source IP disclosure clause. The document must specify the static external IP addresses the testing team will scan from. That way, you can distinguish the test from an actual cyberattack in your WAF and easily filter out test activities if you need to run a forensic analysis on your logs.

HHande V***New memberCommunity member
Joined
Sep 2026
Message
318
#4

The contractual penalties and confidentiality clauses in the agreement should be framed around the cybercrime articles of the Turkish Penal Code and the KVKK. A legally binding protocol for immediate notification and secure deletion must be defined in the event that customer data or sensitive financial records are accessed during testing.

İİsmail Ş***MemberCommunity member
Joined
May 2025
Message
177
#5

Don't open your live database directly to testing. Spin up a test environment that's an exact replica of production, anonymize the sensitive customer data, and run the test there. What matters to banks are the vulnerabilities in your architecture and code; there's no reason to put your live customer table at risk.

AAlper A***MemberCommunity member
Joined
Feb 2026
Message
415
#6

Even if you write a scope document a lot of firms out there just fire up standard automated vulnerability scanners and walk away. If you don't put a cap in the contract like 'automated scanner request rates cannot exceed X requests per second', your API gateway will lock up and your customers will get errors.

TTülay B***Veteran
Job title
Human Resources Manager
Sector
Seafood
Organization type
300-person organization
Joined
Jan 2023
Message
35
#7

Last year we authorized a test for the 02:00-05:00 window. The tester accidentally hammered the prod queue instead of staging, and our messaging server went down for 40 minutes. Luckily we had an emergency stop clause, we killed the test in 3 minutes. Without that clause we never would have made it before the morning shift started.

edit: fixed a few typos.

PPerihan G***Expert
Job title
Administrative manager
Sector
Logistics
Organization type
20-person company
Joined
Feb 2026
Message
283
#8

Will the test be black box or white box? If you're handing source code or API documentation to the team, the clauses covering IP protection and secure destruction of code after the test become far more critical.

SSerkan Ç***MemberCommunity member
Joined
Sep 2024
Message
2
#9

Don't let them ping a single port without written permission; unauthorized access can put both parties straight in front of a public prosecutor.

İİbrahim S***New memberCommunity member
Joined
Jun 2026
Message
20
#10

You're right, I've been down that road too. The real issue isn't the number, but what it's based on.

Correct me if I'm wrong.

HHakan Y***Member
Job title
Production planning
Sector
Seafood
Organization type
20-person company
Joined
Sep 2022
Message
42
#11

I'll try it. When making a decision, first look at what data you have on hand.

Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

EEsra T***Member
Job title
Data Analyst
Sector
Livestock
Organization type
workshop
Joined
Feb 2024
Message
66
#12

you're right. i mean if 2FA is on, a stolen password alone is useless.

having backups accessible on the same network and with the same identity makes them part of the target. btw if you post the result here, it will help others too.

NNeşeNew member
Job title
Hair salon
Joined
Oct 2024
Message
21
#13

Three different views emerged, they all complement each other. The real issue isnt the number but what its based on.

If you post the result here, it will help others too.

AAv. Kemal U***Expert
Job title
Lawyer · IT
Organization type
300-person organization
Joined
Sep 2023
Message
168
#14

Good call starting this thread.

İİlknur G***MemberCommunity member
Joined
May 2025
Message
172
#15

I agree.

HHüsniye U***Member
Job title
Secretary
Sector
Automotive aftermarket
Organization type
boutique agency
Joined
Feb 2025
Message
173
#16

Let me summarize what's been said so far. The answer varies greatly by industry; there is no one-size-fits-all rule.

If it's your first time, start small; scaling comes later. I'm also curious if anyone does it differently.

MMert D***MemberCommunity member
Joined
Dec 2024
Message
3
#17

Noted, thanks. If you get three different answers on a topic, the question was asked wrong.

The real issue isn't the number, but what it's based on.

SSinan T***Member
Job title
Marketing director
Sector
Packaging
Organization type
sole proprietorship
Joined
Aug 2024
Message
27

Doki · Log management setup · 2024

#18

Thanks for writing this, that's the right way. Taking measures without an inventory leaves doors you haven't seen open.

This is my opinion, I'm not claiming it's absolute truth.

LLeyla Y***MemberCommunity member
Joined
Mar 2024
Message
44
#19

i didn't know that. the real issue isn't the nmuber but what it's based on.

MMurat K***Member
Job title
SaaS developer
Organization type
boutique agency
Joined
Mar 2024
Message
118

Doki · Log management setup · 2025

#20

I'd say don't rush. Everyone rushing into penetration testing written authorization gets stuck at the same point.

If you have questions write them; Ill answer as best I can.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic