1. Define the security question
Decide what the organization wants to learn: can an internet attacker reach sensitive systems, can an authenticated user cross authorization boundaries, can a compromised workstation reach privileged infrastructure, or can the detection team see realistic attacker behavior?
2. Confirm scope and ownership
- IP ranges, domains, applications, APIs, cloud accounts, and exclusions
- System owners and emergency contacts
- Third-party systems that require permission
- Production constraints and sensitive operations
3. Prepare access
Create test accounts, VPN access, allow-listing, API credentials, MFA paths, and any temporary roles required by the agreed methodology.
4. Establish communication
Define the primary contact, escalation channel, status cadence, and what should trigger immediate notification.
5. Plan the remediation loop
Know who will own findings, when the debrief happens, and how retesting will be scheduled.
Related next step
Use this resource as a starting point, then adapt it to the systems, business constraints, and threat model that actually apply to your organization.