Ethical Hacking

Paying a trusted expert to attack your own system on purpose, with your written permission, so you find the holes before a criminal does.

Also known as penetration testing pen test white hat hacking

Definition

Ethical hacking means paying someone to attack your own system on purpose. You give written permission first, and you agree in advance what they may touch. The people who do it are usually called penetration testers, and the job is often called a pen test. They use the same tools and the same tricks as a criminal. The difference is that they finish by handing you a report instead of selling your customer list.

The report is what you are really buying, so judge a supplier on it. Every finding stands on its own. Each one carries a severity, meaning how bad the damage would be and how easily someone could do it. Each one carries proof, the exact steps or a screenshot, so nobody on your team can wave it away. Each one carries a fix written in words your developer can act on this week. And the work ends with a retest, where the tester comes back after the repairs and confirms in writing that the hole is closed.

Agree four things before you sign. What is in scope, meaning exactly which addresses, apps and accounts they may touch, and what is off limits. When they may test, because a checkout under attack on a Friday evening is nobody's idea of fun. Who they telephone the minute they find something serious, instead of saving it for the report. And who owns the report afterwards, because a bank or a large customer will ask to see it. Ask as well whether the retest sits inside the price. Very often it does not, and people find that out at the invoice.

Cost follows the days worked, not the tools. A small website is two or three days for one tester. A system with payments, staff roles and a mobile app is two weeks or more. Linkysoft puts this into the plan of every web application project, because a fault caught in a drawing costs an hour and the same fault caught after launch costs a month. If your system is already live and nobody knows where it stands, that is where our cybersecurity work usually starts.

One warning we repeat to every client at Linkysoft. A test proves only what was true on the days it ran. Change the code next month and you have a different system.

Questions about Ethical Hacking

Is ethical hacking legal?
Yes, as long as you hold written permission from the owner of the system saying what may be tested and when. Without that document the same actions are a crime, which is why an honest tester asks for it before touching anything.
How much does a penetration test cost?
Price follows days worked. A small website is usually a few thousand dollars, and a large system with payments and several user types costs much more. Ask how many days you are buying and who exactly will work them.
How often should we have one done?
Once a year for an ordinary business system, and again after any big change, such as a new payment method, a new login screen or a move to a different server.
What is the difference between this and an automatic scan?
A scan is a tool comparing your system with a list of faults other people already found. Ethical hacking is a person who thinks, and who can join two harmless-looking mistakes into one serious break-in.
Will the tester see our real customer data?
Possibly, so settle it in the contract. Many companies hand over a copy of the system filled with fake records, or add a line saying the tester must stop and report the moment real data becomes readable.

Still not sure how this applies to your project?

Tell us what you are building and we will answer in plain language.