Ethical Hacking

Ethical hacking is an attack on your own system that you asked for and paid for, so a trusted expert finds the holes before a criminal does.

Also known as penetration testing pen test white hat hacking

Definition

Ethical hacking means paying someone to attack your own system on purpose, with written permission and an agreement about what they may touch. The people who do this are usually called penetration testers, and the work is called a pen test. They use the same tools and the same tricks as a criminal would, so the difference is not in the method. It is in the ending, because they finish by handing you a report instead of selling your customer list.

The report is what you are really buying, so judge a supplier on it and not on the sales meeting. Every finding should stand alone, starting with a severity for how bad the damage is and how easily it is done. Next to that you want proof, the exact steps or a screenshot, so nobody on your team can wave the finding away. Then comes the fix, written in words your developer can act on this week. The work ends with a retest, where the tester returns after the repairs and confirms in writing that the hole is closed.

Agree four things before you sign, starting with scope, meaning which addresses, apps and accounts they may touch and what is off limits. The second is timing, because a checkout under attack on a Friday evening is nobody's idea of fun. The third is who they telephone the minute they find something serious, instead of saving it for the report. The fourth is who owns the report afterwards, since a bank or a large customer will ask to see it. Ask too whether the retest sits inside the price, because often it does not and people find out at the invoice.

Cost follows the days worked rather than the tools, so a small website is two or three days for one tester. A system with payments, staff roles and a mobile app takes two weeks or more. Linkysoft budgets for this in every web application project, because a fault caught in the drawing costs an hour and the same fault after launch costs a month. If your system is already live and nobody knows where it stands, that is usually where our cybersecurity work starts.

One warning we repeat to every client at Linkysoft is that a test proves only what was true on the days it ran. Change the code next month and you have a different system, so the clean report in your drawer no longer describes it.

Questions about Ethical Hacking

Is ethical hacking legal?
Yes, as long as you hold written permission from the owner of the system saying what may be tested and when. Without that document the same actions are a crime, which is why an honest tester asks for it before touching anything.
How much does a penetration test cost?
Price follows days worked. A small website is usually a few thousand dollars, and a large system with payments and several user types costs much more. Ask how many days you are buying and who exactly will work them.
How often should we have one done?
Once a year for an ordinary business system, and again after any big change, such as a new payment method, a new login screen or a move to a different server.
What is the difference between this and an automatic scan?
A scan is a tool comparing your system with a list of faults other people already found. Ethical hacking is a person who thinks, and who can join two harmless-looking mistakes into one serious break-in.
Will the tester see our real customer data?
Possibly, so settle it in the contract. Many companies hand over a copy of the system filled with fake records, or add a line saying the tester must stop and report the moment real data becomes readable.

Still not sure how this applies to your project?

Tell us what you are building and we will answer in plain language.