Last updated 17 August 2026

Engagement and testing terms

These are the standing rules for how CISO Peak works. They are summarized here so you know what to expect before we talk. The signed agreement for your engagement is the binding document; where the two differ, the signed agreement wins.

Scope comes first

No work starts without a written scope. Before an engagement begins you receive a document naming the systems in scope, the work to be performed, the deliverables, the timeline, and the fee. If the work needs to change once it is underway, that change is agreed in writing before it happens.

Readiness is not a certificate

Framework work is a gap assessment and a plan. SOC 2 reports, HIPAA attestations, ISO certificates, and similar formal opinions are issued by independent auditors or assessors, not by CISO Peak. If you are not ready to sit an audit, that will be said plainly before anyone spends money on one.

Authorized security testing

Testing is performed only under written authorization from someone with the authority to grant it. That authorization records, at minimum:

Where the systems in scope are operated by a third party - a hosting provider, a SaaS vendor, a managed service provider - it is the client's responsibility to confirm that testing is permitted under those contracts, and to obtain the provider's authorization where it is required. Testing does not start until that is confirmed.

If testing surfaces evidence of an active compromise, work pauses immediately and the named contacts are notified before anything else happens.

What testing does and does not prove

A test describes what was found, in the systems in scope, during the testing window, using the agreed techniques. It is a point-in-time assessment. No test proves that a system is secure, and no one who tells you otherwise is worth hiring. Findings are reported with enough detail to reproduce and fix them, prioritized by real risk to your business rather than by scanner severity.

Confidentiality and data handling

Engagements run under a mutual NDA. Access granted is the least needed to do the work, and it is handed back when the work ends. Findings, reports, and any client data collected during an engagement are held only as long as the agreement requires, then destroyed.

Your name is not used as a reference, in a case study, or in any marketing material without your written permission - including the anonymized summaries on the main site.

Independence

CISO Peak sells no security products and takes no commissions, referral fees, or reseller margin from any vendor. When a tool is recommended, it is because it fits the problem. If that ever changes, it will be disclosed to you in writing before the recommendation is made.

Working alongside your team

Engagements are designed to work with your existing IT provider or internal team, not around them. Findings that affect them are shared with them directly where you want that, and recommendations are written to be actionable by the people who will actually do the work.

Fees, invoicing, and cancellation

Engagements are quoted as a fixed fee against a written scope, not billed by the hour, so the number you approve is the number you pay. Ongoing fractional work is invoiced monthly in advance.

Liability

Liability under an engagement is limited to the fees paid for that engagement, except where the law does not permit that limit. Advice is given in good faith on the information available at the time; acting on it, and the decisions that follow, remain yours.

If your procurement process or insurer requires evidence of cover before work starts, raise it during scoping and it will be dealt with in the signed agreement rather than left until the last week.

Governing law

Each engagement agreement names the law that governs it and the venue for any dispute. That is agreed with you in writing before work begins, not assumed - and for clients outside my own jurisdiction it is worth settling early rather than discovering the gap later.

Questions

Anything unclear here is worth asking about before we start: [email protected]. See also the privacy notice for how information from this website is handled.

Back to the site