Skip to content
Safestorm
Menu

Safestorm

A controlled, evidence-led methodology

Every engagement follows clear authorisation, safe testing practices and manual validation.

Safestorm works from objectives rather than finding counts. The methodology is adapted to the target, but authorisation, evidence quality, safe validation and clear communication remain constant.

  1. Step 1

    Define the assurance objective

    Identify critical assets, threat scenarios, user roles, trust boundaries and the decision the assessment must support.

  2. Step 2

    Authorise and make testing safe

    Agree scope, communications, test windows, data handling, prohibited actions, escalation and stop conditions.

  3. Step 3

    Map the effective attack surface

    Discover exposed functionality, services, identities, permissions, routes and dependencies—not only the documented inventory.

  4. Step 4

    Form and test attack hypotheses

    Combine structured coverage, tool-assisted discovery and manual investigation of how a realistic attacker could progress.

  5. Step 5

    Validate and chain weaknesses

    Use proportionate exploitation to confirm impact, then establish whether identity, application or network weaknesses create a wider path.

  6. Step 6

    Explain risk and root cause

    Connect reproducible evidence to affected assets, business impact, compensating controls and the underlying control failure.

  7. Step 7

    Support remediation and retest

    Debrief technical and risk owners, clarify priorities and verify that agreed fixes close the original path.

Tools support judgement

Automated tools can improve coverage and consistency, but scanner output is not reported as a validated finding without expert review. Manual testing examines context, chained weaknesses and business logic that tools often miss.

Safe by design

Proportionate proof

Use the least disruptive evidence needed to demonstrate the risk.

Explicit boundaries

Availability-impacting, destructive or persistence activity is excluded unless separately justified and authorised.

Controlled information

Test data, credentials and evidence are handled under agreed access and retention arrangements.