Briefing
The ethics of penetration testing: six principles a mandate should state
The ethics of penetration testing matter because the techniques are identical to an intruder's. So the only difference is conduct, and conduct should be written down before any work begins.
- Principal-led mandates
- Fixed fee agreed in writing
- Nothing retained afterwards
Why the ethics of penetration testing must be written
A buyer cannot watch every step of a test. Therefore the principles that govern the work belong in the engagement letter, where both sides can hold each other to them.
Six principles in the ethics of penetration testing
These six appear in every Sentinel Black mandate, in plain words.
| Principle | In practice |
|---|---|
| Authorisation | Written permission from the system owner first. |
| Scope | Nothing outside the list, however tempting. |
| Proportion | No more access or disruption than the objective needs. |
| Confidentiality | Mutual non-disclosure, and no client named without consent. |
| Data handling | Encrypted while live, destroyed at close. |
| Disclosure | Findings go to the owner only. |
Check a provider against the ethics of penetration testing
Tick each item a provider has committed to in writing.
Your result appears here as you tick, so you can see what is still open.
When the ethics of penetration testing require a stop
Sometimes a test finds something nobody expected. For example, signs of a real intruder already present, or data that should never have been there. In that case the work pauses, and the named contacts are told at once.
Requests that fail the ethics test
Some requests arrive often, so we say this plainly. We decline access to anyone's account or device without the owner's consent. We also decline surveillance of individuals and retaliation against attackers, because that belongs with law enforcement.
How Sentinel Black applies these principles
A senior professional hacker leads every mandate, so one person is accountable for conduct. Full mandates run from $35,000 to $120,000, while the floor is $25,000. Also, the bounded Exposure Assessment starts at $4,500. Moreover, its fee is credited in full against a full engagement commissioned within ninety days.
Questions on the ethics of penetration testing
Who sets the ethics of penetration testing?
Published methods and the law set the floor. The engagement letter then states the rest.
Is the ethics of penetration testing just legal compliance?
No. Proportion and data handling go further than the law requires.
What if a tester finds an existing breach?
The work pauses, and the named contacts are told immediately.
Can findings be shared with anyone else?
Only with the owner's written consent.
Related guides
Request an introduction
Tell us what you need protected. The engagement letter, with every principle above, is signed before any technical discussion begins. Also, tell us who will sign the authorisation, because that person holds the scope and agrees every principle in it. Every exchange stays in writing, so it is on record.
Request an introduction