How to prepare for an authorized website security test
Make the scope concrete
Write down exact hostnames and applications. Identify third-party services and check whether separate approval is needed. A domain registration or invoice is useful context, but should not be treated as permission to test every connected service.
Plan around real operations
Tell the tester about fragile integrations, maintenance windows and actions that generate customer emails or financial events. Use approved test data where possible. Decide how both sides will communicate if an unexpected effect appears.
Prepare the handover
Name someone who can receive the report and someone who can implement changes. Agree the preferred report language and secure delivery method. MoShield's request workflow starts with contact and scope confirmation; submitting a form does not itself start testing.
Practical checklist
- Confirm exact targets and exclusions.
- Agree permitted actions and a stop condition.
- Provide an operational contact.
- Confirm report recipient and language.
A common question
Can testing start as soon as I submit the form?
No. Scope, authorization and the service arrangement must be confirmed first. Use the consultation process to resolve missing details.
Source and further reading
OWASP WSTG: reporting scopeGeneral educational guidance, not a finding about your systems. Testing requires an agreed scope and authorization.