Skip to main content
GullySystem

Notes for owners · Industry-Specific Software Guides

How to Set Up an Engagement Register for a Security Testing Firm

Set up an engagement register by giving every job one record that holds the signed scope, the testers, the findings, the review and the retest. GullySystem builds this as a custom system for security firms, and it records the work your testers do. It does not run the tests.

Ganesh HS, Strategy and Technology, GullySystem · · 3 min read

Start with one record per engagement

Each engagement gets one record the day it is agreed. It holds the client, the type of work, the test window, the assigned testers and the stage it has reached.

Stages are plain words your team already uses: scoping, in testing, in review, report sent, fixes pending, retest, closed. A manager scanning the list can see where every job stands.

  • Client and primary contact
  • Type of work and test window
  • Testers and reviewer by name
  • Stage and next date

Attach the scope and the authorisation

The written scope is the most important paper in the job. It names the targets, the dates and what is excluded. Keep the signed copy on the record, not in a mailbox.

Testers then work against something they can read. A question about whether a host was in scope is answered in a minute rather than argued after the report is sent.

Log findings once, in one place

Each finding gets a title, a severity, the affected asset, the evidence and a suggested fix. Testers add them on the engagement record as they go, not in personal files.

A reviewer checks each finding before it enters the report. This removes duplicates and catches thin evidence while the tester still remembers the detail.

  • Severity chosen from your own scale
  • Evidence attached to the finding
  • Reviewer’s name and date
  • Status: open, fixed, retested or accepted by the client

Keep versions of the report and track the retest

Record each issued version of the report with its date and who approved it. If a client says they received an earlier draft, the register shows what was sent.

After the client fixes issues, the retest is a stage on the same record. Findings move to retested, and the closure summary is built from them. Nothing waits on someone’s memory.

Add retainers, renewals and access

Many firms also sell monitoring retainers and resold licences. Put hours per month and licence due dates on the client record, so renewal quotes are made before anything lapses.

Limit each engagement to the people working on it, and log who opens or downloads a report. Client data then reaches only the people who need it.

Engagement record template

A one-page template with fields for client, scope, test window, testers, stage, findings and retest date. Fill one for each live engagement and pin the list where the manager sees it daily. Add a column for the next action and its owner.

Open a blank worksheet to print

Questions owners ask

Can the register run our scans?

No. Your own tools do the testing. The register records scope, findings, review and retest, and can take in a file exported from a scanner after a tester has checked it.

Should small firms use a spreadsheet instead?

For a handful of engagements a year, a spreadsheet and a folder can be enough. A register starts to pay off when several testers work at once and retests slip.

Does it make our firm certified?

No. It keeps the records a client or auditor may ask for. Any certification of your firm stays between you and the body that grants it.

Can clients see their own findings?

It can be built that way, with a login that shows only their reports and finding status. Many firms prefer to send protected files, and either choice is made at scoping.

Next step

Have a specific situation to work through?

This article covers the general case. Tell us what you’re actually dealing with and we’ll respond directly.

See software for cybersecurity companies