Ethical Hacking
Ethical hacking is an attack on your own system that you asked for and paid for, so a trusted expert finds the holes before a criminal does.
Also known as penetration testing pen test white hat hacking
Definition
Ethical hacking means paying someone to attack your own system on purpose, with written permission and an agreement about what they may touch. The people who do this are usually called penetration testers, and the work is called a pen test. They use the same tools and the same tricks as a criminal would, so the difference is not in the method. It is in the ending, because they finish by handing you a report instead of selling your customer list.
The report is what you are really buying, so judge a supplier on it and not on the sales meeting. Every finding should stand alone, starting with a severity for how bad the damage is and how easily it is done. Next to that you want proof, the exact steps or a screenshot, so nobody on your team can wave the finding away. Then comes the fix, written in words your developer can act on this week. The work ends with a retest, where the tester returns after the repairs and confirms in writing that the hole is closed.
Agree four things before you sign, starting with scope, meaning which addresses, apps and accounts they may touch and what is off limits. The second is timing, because a checkout under attack on a Friday evening is nobody's idea of fun. The third is who they telephone the minute they find something serious, instead of saving it for the report. The fourth is who owns the report afterwards, since a bank or a large customer will ask to see it. Ask too whether the retest sits inside the price, because often it does not and people find out at the invoice.
Cost follows the days worked rather than the tools, so a small website is two or three days for one tester. A system with payments, staff roles and a mobile app takes two weeks or more. Linkysoft budgets for this in every web application project, because a fault caught in the drawing costs an hour and the same fault after launch costs a month. If your system is already live and nobody knows where it stands, that is usually where our cybersecurity work starts.
One warning we repeat to every client at Linkysoft is that a test proves only what was true on the days it ran. Change the code next month and you have a different system, so the clean report in your drawer no longer describes it.
Questions about Ethical Hacking
Is ethical hacking legal?
How much does a penetration test cost?
How often should we have one done?
What is the difference between this and an automatic scan?
Will the tester see our real customer data?
Still not sure how this applies to your project?
Tell us what you are building and we will answer in plain language.