Skip to content

Example engagements

From first conversation to final report. Here's what that looks like in practice.

Working with Ingenium is a structured, collaborative process, designed to be clear at every stage, and to generate value at each one. From discovery through to reporting, here is exactly what a typical engagement looks like, and what you take away from it.

Structured by design. Valuable at every step.​

Independent testing is not a black box. You should know what happens at each stage, what we need from you, and what you gain before the final report lands.

The process below reflects how we approach every engagement, methodically, transparently, and with your business outcomes in mind throughout. The scope and timelines will vary depending on the depth and type of testing involved. The structure does not.

The engagement process

The nine stages of an Ingenium engagement

Stage 1: Discovery

What happens: We begin with a detailed consultation to understand your objectives, your technology stack, your risk profile, and your regulatory context. We ask the questions that surface what you actually need, not just what you think you need.

What you get: Clarity. A structured conversation with independent experts who have no stake in the technology you’ve deployed – and no incentive to tell you what you want to hear. Many clients find this stage alone reshapes how they think about their testing requirements.

Stage 2: Proposal and scoping

What happens: We design a tailored testing approach based on what we’ve learned. This includes defining scope, selecting methodology, agreeing on instruments and attack methods, and setting commercial terms. Nothing proceeds until scope is agreed and understood by both parties.

What you get: A written proposal that makes your testing programme legible – what will be tested, how, at what level of coverage, and why. For many organisations, this document becomes an internal reference point for communicating the value of testing to stakeholders who weren’t in the room.

Stage 3: Kick-off

What happens: We align on practical working arrangements: access requirements, data flows, points of contact, confidentiality, and timelines. We ensure all parties understand their responsibilities before anything begins.

What you get: A shared operating framework that protects both sides and removes ambiguity from the process. For regulated organisations, this is also when we establish how findings will be documented and what level of detail your compliance or legal team will need.

Stage 4:  Environment setup and QA

What happens: We configure the test environment and conduct quality assurance checks to validate that the setup is fit for purpose before testing begins. We identify and resolve any technical blockers at this stage – not mid-test.

What you get: Confidence that the results will be defensible. If the test environment is not correctly configured, results cannot be relied upon. This stage protects the integrity of everything that follows, and it is where corners are never cut.

Stage 5: Test launch (entry gate)

What happens: A formal checkpoint. We confirm that all conditions are met, all parties are ready, and all prerequisites are satisfied before live testing begins. If anything is not right, we pause – not proceed.

What you get: An independent quality control mechanism that protects the validity of your results. The entry gate exists because a compromised test produces compromised evidence – and compromised evidence is worse than no evidence at all.

Stage 6:Test execution

What happens: We conduct rigorous testing aligned to your agreed scope and methodology. Depending on the engagement, client involvement may range from minimal – where you simply await findings — to highly collaborative, where your internal team works alongside ours to understand the threat landscape in real time.

What you get: Empirical evidence of how your system performs under real-world attack conditions. Not a theoretical assessment. Not a vendor-controlled benchmark. A reproducible, scientifically valid record of how your system actually behaves against the methods threat actors are using today.

Stage 7:  Test completion (exit gate)

What happens: A structured close to the testing phase. We verify completeness, confirm the integrity of results, and formally conclude the live testing period. Nothing moves to analysis until this gate is satisfied.

What you get: An unambiguous endpoint. For organisations operating in regulated environments, the exit gate creates a clear audit trail – confirming when testing concluded and that all agreed activities were completed before analysis began.

Stage 8: Analysis and reporting

What happens: We analyse the full dataset and produce a detailed report covering findings, metrics, vulnerabilities identified, and recommendations. Reports are structured to serve multiple audiences – from technical teams who need granular detail to executive stakeholders and regulators who need clear conclusions.

What you get: A report that works as hard as the testing did. Findings are presented with the evidence to support them, the context to interpret them, and the recommendations to act on them. For vendors, this document becomes part of your product’s independent assurance story. For buyers, it becomes the foundation for procurement decisions, regulatory conversations, and internal risk management.

Stage 9: Results presentation and ongoing Support

What happens: We present findings directly, answer questions, and support you in communicating results – whether internally, to regulators, to procurement partners, or to the market. We do not hand over a report and disappear.

What you get: An expert partner in the room when the results matter most. We understand how regulators read test data. We understand what procurement teams need to see. And we understand that the value of a test report is only realised if the findings are understood and acted upon. This stage is where that happens.

Testing is not a one-time event.

The threat landscape doesn’t stay still, and neither should your assurance. Many organisations return to Ingenium on a recurring basis – to re-test following system updates, to test against newly identified attack methods, or to expand the scope of coverage as their security posture matures.

Your first engagement establishes a baseline. Every subsequent engagement builds on it.

Ready to start the conversation?

Whether you’re new to biometric and identity testing or looking to go further than your current programme allows, we’ll begin where it makes sense – with a straightforward conversation about your objectives, your systems, and what you need to know.