Safestorm works from objectives rather than finding counts. The methodology is adapted to the target, but authorisation, evidence quality, safe validation and clear communication remain constant.
- Step 1
Define the assurance objective
Identify critical assets, threat scenarios, user roles, trust boundaries and the decision the assessment must support.
- Step 2
Authorise and make testing safe
Agree scope, communications, test windows, data handling, prohibited actions, escalation and stop conditions.
- Step 3
Map the effective attack surface
Discover exposed functionality, services, identities, permissions, routes and dependencies—not only the documented inventory.
- Step 4
Form and test attack hypotheses
Combine structured coverage, tool-assisted discovery and manual investigation of how a realistic attacker could progress.
- Step 5
Validate and chain weaknesses
Use proportionate exploitation to confirm impact, then establish whether identity, application or network weaknesses create a wider path.
- Step 6
Explain risk and root cause
Connect reproducible evidence to affected assets, business impact, compensating controls and the underlying control failure.
- Step 7
Support remediation and retest
Debrief technical and risk owners, clarify priorities and verify that agreed fixes close the original path.
Tools support judgement
Automated tools can improve coverage and consistency, but scanner output is not reported as a validated finding without expert review. Manual testing examines context, chained weaknesses and business logic that tools often miss.
Safe by design
Proportionate proof
Use the least disruptive evidence needed to demonstrate the risk.
Explicit boundaries
Availability-impacting, destructive or persistence activity is excluded unless separately justified and authorised.
Controlled information
Test data, credentials and evidence are handled under agreed access and retention arrangements.