Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you need an expert to find weaknesses in a system, hire a penetration-testing provider and authorize a clearly bounded test in writing. Choose a team with skills relevant to your technology, agree what it may test and how it must protect your systems, and require a report that helps you fix the findings. A penetration test is evidence about specified assets at a particular time—not proof that a system is secure.

Should you hire an ethical hacker?

Consider commissioning a penetration test when you need an expert assessment of technical risk in an operational system—for example, before a launch, to examine a particular concern, or to evaluate defined controls. Experienced testers may uncover subtle weaknesses that routine internal processes miss. The UK National Cyber Security Centre (NCSC) describes penetration testing as a core security tool, but cautions that it is not a magic bullet: it should complement, not replace, an ongoing internal assessment and vulnerability-management program. NCSC guidance on penetration testing.

A penetration test and a vulnerability scan serve different purposes. Microsoft describes penetration testing as authorized experts simulating attacks to identify and exploit weaknesses; scanning uses automated tools to look for known vulnerabilities. Organizations may use both: scanning can help identify known issues routinely, while a scoped test can examine how weaknesses might be reached or combined. Neither approach establishes that every vulnerability has been found. Microsoft’s penetration-testing rules.

How to hire a penetration tester

  1. Define the decision and system boundary

    Write down what the test should help you decide: such as whether a defined system is ready to launch, how a particular risk affects it, or whether specified controls work as intended. Map the operational system and connected components, rather than assuming the application alone is the whole scope. Depending on the service, relevant interactions may involve infrastructure, physical access, or people and processes. Involve the risk owner, staff who understand the technology, and the prospective provider when setting boundaries. The NCSC model and GOV.UK Service Manual guidance discuss scoping and the need to consider the service as a whole.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Match the provider to your technology

    Ask about the proposed team’s relevant qualifications and recent experience with systems like yours. Explain unusual platforms, protocols, bespoke hardware, and operational constraints before comparing bids. Ask the provider to describe its approach, expected effort, and how it will handle those specifics. There is no universally best provider established by these sources; compare the fit of the team’s skills and proposal to your estate.

    Credential requirements depend on context. For relevant UK government work, NCSC guidance recommends CHECK teams for HMG organizations, and the GOV.UK Service Manual recommends CHECK-certified teams or staff accredited to equivalent CHECK levels for its applicable services. These are context-specific recommendations, not a universal rule for every organization or country. See NCSC guidance and the GOV.UK Service Manual.

  3. Put permission and rules of engagement in writing

    Before work starts, confirm that you own each target or have written authority from the party that does. Record the exact domains, IP ranges, applications, cloud tenants, facilities, and third-party dependencies in scope. Also specify allowed methods, prohibited actions, test dates and hours, any rate or traffic limits, test accounts, data handling, emergency contacts, stop-work triggers, and how changes to scope will be approved. Make clear how the tester should report a critical issue or unexpected impact.

    Obtain explicit supplier consent before including a third party’s software or systems. The GOV.UK Service Manual says that explicit consent is needed when testing third-party software used in a service. Microsoft’s rules likewise prohibit activity against assets or data without permission under its policy. The policies illustrate why precise authorization matters; neither is blanket permission to test other organizations’ systems. See the GOV.UK Service Manual and Microsoft’s rules.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  4. Agree the report and severity scheme in advance

    Set expectations for who will read the results and how findings will be prioritized. Require an executive summary understandable to decision-makers as well as technical evidence that engineers can use to investigate and reproduce findings. The report should include the tested scope and limits, risk or severity ratings, and practical remediation advice. Agree what the severity labels mean rather than assuming two providers use them identically. The GOV.UK Service Manual emphasizes reporting that serves both nontechnical decision-makers and technical teams; NCSC’s model covers reporting requirements as part of the engagement. See the GOV.UK Service Manual and NCSC guidance.

  5. Stay reachable, then fix and verify

    Assign a technical contact who can answer questions, resolve blockers, and receive urgent findings while testing is underway. Agree how disruptive effects should be managed. NCSC says providers should try to avoid undue impact, but no plan can guarantee that unexpected reactions will not occur. Afterward, review the findings with the relevant owners, prioritize fixes according to your organization’s risk, and verify remediation. The provider’s report informs your decisions; responsibility for accepting risk and fixing issues remains with your organization.

What should a penetration-testing contract cover?

Make the contract or accompanying rules-of-engagement document specific enough that both sides can tell what is authorized and what is not. NCSC’s model guidance describes documenting technical boundaries, test types, timing and effort, possible scenarios, tester requirements, compliance obligations, reporting requirements, and time constraints. For a practical checklist, ensure the written agreement covers:

  • Authority and scope: named assets, environments, locations, and third-party dependencies, plus evidence that the customer can authorize testing.
  • Permitted activity: methods the provider may use, actions it must not take, and any limits on traffic, access, data, or accounts.
  • Schedule and safety: dates and hours, emergency and escalation contacts, stop-work conditions, and a process for approving scope changes.
  • Data and findings: how sensitive information and test evidence will be handled, who may receive the report, and how urgent findings are communicated.
  • Deliverables and follow-up: report format, agreed severity scheme, remediation guidance, debrief, and any retesting or follow-up support.

For UK government services, the Service Manual advises involving security and legal teams in third-party testing arrangements, including supplier permission, timing, and staff-focused tests. It says third-party reports should be handled as OFFICIAL-SENSITIVE in that government context; this classification should not be generalized to other organizations. GOV.UK Service Manual.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is hiring an “ethical hacker” legal?

The label does not grant permission. Testing is authorized only to the extent that the relevant owner or authorized party has agreed to the assets and methods involved. A vulnerability disclosure policy or vendor testing program applies within its stated terms and scope; it does not authorize testing unrelated systems.

Microsoft’s policy, for example, prohibits unauthorized access, customer-data access, denial-of-service testing, and post-exploitation actions for Microsoft assets under that policy. The US Department of Justice’s vulnerability disclosure policy is another example of bounded permission: it warns that activity inconsistent with the policy may carry criminal or civil liability and does not claim to shield all activity everywhere. These policies illustrate limits; they do not settle the law for every jurisdiction, contract, or asset. If ownership, authority, or applicable law is unclear, get jurisdiction-specific legal advice before testing. See Microsoft’s rules and the DOJ vulnerability disclosure policy.

How much does a penetration test cost?

There is no supported price or market average established here. Cost depends on the agreed scope, technology, constraints, provider, and required deliverables, so compare written proposals that describe what is included rather than relying on an unqualified headline price. Ask each candidate to explain its assumptions, effort, exclusions, and any follow-up work separately.

What a penetration-test result can—and cannot—tell you

Read findings as evidence about the assets and methods included in the engagement on the test date. A clean report does not prove the absence of vulnerabilities, cover assets outside scope, or guarantee security after systems change. NCSC characterizes a test as validating against known issues on the day of testing, not as an enduring assurance. Continue routine security testing and vulnerability management, and repeat or adapt testing when systems, exposure, or risks change. NCSC guidance; see also NIST’s foundational Technical Guide to Information Security Testing and Assessment, finalized 30 September 2008.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.