A professional hacker, retained rather than hired
Sentinel Black is a small practice. Every mandate is led personally by a senior professional hacker, so the person you meet is the person on your systems from first day to last. We accept a limited number of engagements each year.
Most firms sell you a brand, but the professional hacker who turns up is whoever is free that month.
We sell the opposite. A named professional hacker, a fixed fee, and a written boundary neither of us crosses.
What a professional hacker is retained to do
An engagement is a judgement about people before it is a purchase. Therefore these five commitments sit here rather than in the small print, because they are what you are actually buying.
Why a professional hacker is judged on discretion
Our institutional practice comes first. Our professional hackers work with security teams inside large organisations, on retainer and on named engagements, and that is the bulk of the year.
Alongside it we take a small number of private mandates. Those are reserved for founders, executives, and families facing a technically complex threat, and a senior professional hacker leads them directly. We do not advertise that side of the practice, so it arrives by introduction.
In either case the engagement letter is signed before any technical discussion begins. Consequently nothing sensitive ever travels over an unprotected channel.
Professional hacker terms, before anything technical
Every professional hacker mandate runs on the same terms. They are short on purpose, since a clause nobody reads protects nobody.
- Authorisation
- Written permission from the system owner, obtained before any technical work.
- Scope
- A defined list of systems, with everything outside it explicitly out of bounds.
- Confidentiality
- Mutual non-disclosure signed first, and no client named without written consent.
- Fee
- One fixed number, agreed after scoping, invoiced against milestones.
- Insurance
- Professional indemnity and cyber liability cover, evidenced on request.
- Retention
- Nothing kept. Evidence and findings destroyed when the engagement closes.
Engagements we decline
We say this plainly because the request arrives often, and a polite silence helps nobody.
- Access to any account, device or system without the owner's documented consent.
- Surveillance of a private individual, whatever the relationship to the requester.
- Recovery of an account that belongs to somebody else.
- Alteration of records, balances or logs held by another party.
- Identifying or retaliating against whoever attacked you. That belongs with law enforcement.
Unauthorised access is a criminal offence in both jurisdictions where we operate, and in the United Kingdom it is an offence regardless of intent. If a request touches the list above, we are not the right firm, and it receives no reply.
One professional hacker finding, redacted
We publish no case studies with names on them. However, the shape of the work can be shown, so here is a single critical finding from an authorised engagement.
- Client
- Retail group, North America
- Entry
- A build runner token left readable in a public job log
- Chain
- Token to over-scoped role to vault path to backup operator to domain controller
- Elapsed
- 41 hours from the opening of the testing window
- Impact
- Full control of the production identity plane
- Remedy
- Three configuration changes, no downtime, confirmed on the included retest
Where a full professional hacker mandate usually settles. The floor for a full mandate is $25,000, while red team work begins higher.
The fee is fixed after a written scoping brief, so there is no hourly billing and no revision mid-engagement. We hold premium work at set rates, therefore where a budget will not carry a scope we change the scope rather than the standard. Moreover, the bounded assessment below is a different mandate for exactly that situation.
A bounded professional hacker assessment
from $4,500 Second doorThe Exposure Assessment is a bounded review of what you expose to the internet. We map your public estate, test it, and verify every finding by hand rather than sending you a scanner export. Scope is fixed at up to five external hosts and one public web application. Your report then arrives within five business days.
Suited to
- An enterprise customer, an insurer or an investor has asked for evidence of testing, and you have a date to meet.
- Nothing external has ever been tested, so you first need to know what is actually reachable.
- You would rather see how we work on something small before committing to a full programme.
Not this engagement
- Internal network, Active Directory or cloud role review.
- Business logic testing, or work that reads your source code.
- Full exploitation chains against a defended estate.
- Auditor-grade evidence for SOC 2 or PCI, which needs the full engagement above.
The fee is credited in full. Commission a full engagement within ninety days of your report and the whole review fee comes off the price. Consequently the review costs you nothing if you go on to the deeper work.
This is a different engagement, not a smaller version of the one above. Moreover, it is priced by scope rather than by depth of care. Consequently, where the review finds something that needs the deeper work, we say so plainly and quote it separately.
Questions about retaining a professional hacker
What does a professional hacker actually do?
In short, a professional hacker runs authorised attack simulation. We attempt to reach something valuable using the same methods a real intruder would, then hand back the route, the evidence, and the remedy. Written permission from the system owner is what separates the profession from the offence.
Why will you not show client logos?
Because our clients hire us on the understanding that the engagement stays private. A logo wall would break that on day one. Instead we put you in touch with a comparable client once mutual non-disclosure is in place.
Will a professional hacker work with private individuals?
We accept a small number each year, usually founders, executives, or families facing a genuine and technically complex threat. A senior principal leads that work directly, and the terms are identical to our institutional mandates.
How do you handle confidentiality?
Your professional hacker signs mutual non-disclosure before any technical discussion. Evidence moves over encrypted channels while the work is live, and everything is destroyed when the mandate closes. Moreover, no engagement is subcontracted, so the circle stays small.
What does a professional hacker cost?
A full professional hacker mandate starts at $25,000, and most settle between $35,000 and $120,000. Alternatively, the bounded Exposure Assessment starts at $4,500. The number is fixed after the written scoping brief in both cases. We hold set rates, therefore where a budget cannot carry a depth we change the scope rather than the rate. Moreover, the assessment fee is credited in full against a full mandate commissioned within ninety days.
How quickly can you begin?
That depends on professional hacker capacity, since we run a limited number of engagements at once. Where a window is free, work usually begins within two weeks of the signed engagement letter.
Briefings
Briefings from a professional hacker practice
Each briefing covers one decision for leadership, from mandate to deliverables.
- Penetration testing for banks
- Enterprise penetration testing
- Penetration testing in cyber security
- Ransomware penetration testing
- Ethics of penetration testing