Skip to content
Legal · Template

Rules of Engagement

Every CyberZ engagement is governed by written Rules of Engagement agreed before testing. This page shows the structure we use. It is a template, not a contract: the final document is completed per engagement and must be reviewed by your legal counsel and ours.

Last updated: [date]

Template — requires legal review

This structure is provided for transparency. It is not a downloadable legal document. The executed Rules of Engagement are attached to the engagement agreement and require legal review on both sides.

1. Parties and authorization

Names of the customer and CyberZ, the authorized signatory on the customer side who is entitled to grant testing permission, and confirmation that the customer owns or has the right to authorize testing of every in-scope target.

2. Authorized targets

Exact hostnames, IP addresses or ranges, applications, APIs, cloud accounts, environments and test accounts that may be tested.

3. Prohibited targets

Systems explicitly excluded, including third-party services, shared infrastructure and any production data stores excluded by the customer.

4. Testing window

Dates and hours during which testing may occur, blackout periods, and the time zone that applies.

5. Source IP addresses

Addresses from which testing traffic originates, where applicable, so it can be identified and allowlisted or monitored.

6. Testing methods

Permitted techniques: manual testing, automated scanning, credentialed testing, and any methods excluded by agreement.

7. Exploitation limits

How far a confirmed vulnerability may be exploited: proof-of-concept only, limits on data access, no persistence, no modification of production data unless expressly agreed.

8. Social engineering

Whether phishing or other social engineering is included, and if so, the permitted targets, pretexts and approvals required. Excluded unless stated.

9. Denial-of-service restrictions

Denial-of-service and resource-exhaustion testing are excluded by default and performed only with explicit written agreement and controls.

10. Data handling

How data encountered during testing is minimized, captured as evidence, stored, transferred and destroyed, and the retention period that applies.

11. Emergency contacts

Named contacts on both sides reachable during the testing window, with escalation paths.

12. Stop conditions

Events that pause or end testing immediately: system instability, unexpected exposure of sensitive data, detection of a third-party compromise, or a request from the customer.

13. Communication channels

Where status updates, critical findings and questions are exchanged, and how those channels are secured.

14. Reporting and retest

Report delivery method, retest window and the conditions under which a CyberZ Penetration Testing Certificate is issued.

Contact

Questions about this document: contact@cyberz.net.