Ethical Hacking
Paying a trusted expert to attack your own system on purpose, with your written permission, so you find the holes before a criminal does.
Also known as penetration testing pen test white hat hacking
Definition
Ethical hacking means paying someone to attack your own system on purpose. You give written permission first, and you agree in advance what they may touch. The people who do it are usually called penetration testers, and the job is often called a pen test. They use the same tools and the same tricks as a criminal. The difference is that they finish by handing you a report instead of selling your customer list.
The report is what you are really buying, so judge a supplier on it. Every finding stands on its own. Each one carries a severity, meaning how bad the damage would be and how easily someone could do it. Each one carries proof, the exact steps or a screenshot, so nobody on your team can wave it away. Each one carries a fix written in words your developer can act on this week. And the work ends with a retest, where the tester comes back after the repairs and confirms in writing that the hole is closed.
Agree four things before you sign. What is in scope, meaning exactly which addresses, apps and accounts they may touch, and what is off limits. When they may test, because a checkout under attack on a Friday evening is nobody's idea of fun. Who they telephone the minute they find something serious, instead of saving it for the report. And who owns the report afterwards, because a bank or a large customer will ask to see it. Ask as well whether the retest sits inside the price. Very often it does not, and people find that out at the invoice.
Cost follows the days worked, not the tools. A small website is two or three days for one tester. A system with payments, staff roles and a mobile app is two weeks or more. Linkysoft puts this into the plan of every web application project, because a fault caught in a drawing costs an hour and the same fault caught after launch costs a month. If your system is already live and nobody knows where it stands, that is where our cybersecurity work usually starts.
One warning we repeat to every client at Linkysoft. A test proves only what was true on the days it ran. Change the code next month and you have a different system.
Questions about Ethical Hacking
Is ethical hacking legal?
How much does a penetration test cost?
How often should we have one done?
What is the difference between this and an automatic scan?
Will the tester see our real customer data?
Still not sure how this applies to your project?
Tell us what you are building and we will answer in plain language.