Summary
You’ll have a report you can hand to an auditor or a board, plus a fix list your technical team can work through without guessing what I actually proved.
You reached out because you need a test on file for audit, insurance, or a customer, or you want an independent check before a portal goes live. I keep scope and rules tight so testing produces evidence without creating downtime. If you’d like to move ahead, the next step is a short scoping call.
I start by agreeing scope in writing, then I test only what you sign off. During active testing I focus on paths that lead to real impact, and I validate findings with proof that can be replayed. I plan around production hours and account lockout thresholds so operations keep running.
Who you are working with
I’m Matthias Hofer, a penetration tester. I do focused security testing for organisations that need an answer they can stand behind later. Most of my work starts with a simple request: prove what an attacker can do, using the same access and constraints I would have in the real world, and write it down so it holds up.
People hire me when they want a pen test that stays readable under pressure. I keep scope, credentials, and test windows explicit so nobody is surprised. I avoid vague “high risk” language and I attach evidence to each finding so your team can reproduce it, patch it, and show the before and after.
Recent projects
Here are three recent penetration testing engagements that show how I scope, test, and document evidence for sign-off.
Portfolio
External network test. Tested internet-facing assets against the agreed IP ranges and domains, then validated the few paths that mattered. Delivered findings with reproduction steps and screenshots so the client could prove fixes to an auditor without a follow-up call.
Customer portal web test. Tested authentication, session handling, and data access controls in a pre-release portal. Confirmed which issues were exploitable with a standard user account, then re-tested after patches to confirm the exploit chain no longer worked.
Internal network test. Worked from a controlled internal foothold and mapped lateral movement paths that could reach sensitive systems. Focused on credential exposure and privilege escalation, then documented the exact pivot steps so remediation could be verified in a change window.
“Clear scope, no surprises, and the report answered every audit question.”
IT manager, a mid-sized manufacturer
My approach
I run penetration testing like a controlled exercise: agreed scope first, then a planned window, then evidence that stands up to review. You’ll always know what I’m testing, what access I’m using, and what might create noise in your environment.
1. Scope and rules Days 1-2 I confirm what is in scope and out of scope, what success looks like, and what safety limits apply. We agree the testing window, monitoring contacts, and lockout thresholds. If you need VPN access or test accounts, I specify exactly what I need and how I will store it. 2. Inventory and plan Days 2-4 You provide the final asset list for the agreed test type, and I turn it into a test plan you can sign off. This is where you catch surprises like third-party hosted services, legacy IP ranges, or production systems that must not be stressed. 3. Active testing Days 5-10 I perform hands-on testing against the signed-off scope and I prioritise exploit paths that lead to real access or data exposure. I keep attempts controlled to reduce account lockouts and unnecessary load. If I find a path that could cause disruption, I stop and confirm before pushing further. 4. Validation and handover Days 11-14 I validate findings with proof, capture evidence, and write up exactly how each issue was confirmed. Then we do a remediation call to walk through priority and sequencing. If you fix quickly, I can re-check the specific items during the engagement so you have confirmation in the final report.
Fees
Pick the tier based on how many environments and paths you need tested, and how much evidence you need the report to carry for audit and insurance.
Priced items
Next steps
If you want this booked in, I can lock dates once the scope and access approach are agreed.
1. Sign this proposal and choose your preferred testing window. 2. Pay the 50% booking invoice to reserve the dates. 3. Join a 30-minute scoping call so I can write the rules of engagement.
Signature
Fee summary
Payment
To book the engagement, the invoice for 50% is due when you sign. The remaining 50% is invoiced when the engagement is complete. Each invoice is payable within 14 days of its date.
Scope. Penetration testing only covers what we both list in the scope and rules of engagement. Anything not listed is out of scope. If you want to add or change targets, I will confirm the change in writing before I test.
Access and timing. You will provide working VPN or allowlisted access, and test credentials where needed, by the start of Day 5. If access is not ready, the active testing window moves, because I cannot safely validate findings without it.
Production safety. I will plan noisy or high-risk checks into an agreed testing window and avoid denial-of-service style testing unless you explicitly approve it. If I see a risk of lockout or outage, I will stop and contact you before continuing.
Credentials and data handling
I only store the credentials and keys I need to run the test, and I keep them in an encrypted vault. I will not copy business data unless it is required as evidence, and any evidence stays limited to what proves access.
Evidence and reporting. The report documents what was tested, what was proven, and how it was proven, with timestamps and clear reproduction notes where that is safe. If you need a specific format for audit or insurance, tell me at scoping.
Change pauses. If a major system change lands during Days 5 to 10, the results can stop matching what is live. In that case I will pause, confirm what changed, and agree with you whether to re-test the affected area.
Ownership and use. Once the engagement is paid in full, you own the report and can share it with auditors, insurers, and customers. I will not reuse your names, IPs, screenshots, or findings in marketing or talks without your written approval.






