Pentester

Pentester

A pentester is a paid professional who, on behalf of a company, attempts to break into its computer systems — to find security gaps before real criminals exploit them. The attack is authorized in writing beforehand, and the result is a report with suggestions for improvement.

A pentester attacks computer systems — but with explicit written permission from the owner. The name comes from “penetration test”: you’re testing whether someone can break into a system. The task is to find weaknesses before someone with bad intentions finds them. A fitting comparison: a bank hires someone to try to get into the vault. If they find a way in, the gap is closed and no one gets robbed. That’s exactly the business model of this profession.

Attack on request instead of damage control

Companies usually check their software to see whether it does what it’s supposed to do. A pentester checks the opposite: what it can do even though it’s not supposed to. Developers often lack this perspective because they know their own system only from the inside. An outsider tries things that no one thought of during design.

The economic reason is simple. A data breach can quickly cost a mid-sized company millions — through operational downtime, litigation, and loss of customer trust. A penetration test costs a five-figure sum depending on scope. For many industries it’s mandatory anyway: banks, hospitals, and payment service providers must regularly prove that they have their systems tested.

The distinction from a criminal is important. The difference between a pentester and an attacker lies not in the tools but in the mandate. Both use the same methods. Only one of the two has a contract that precisely specifies which systems they may attack and which they may not.

From finding the gap to the report

A test begins with reconnaissance. The pentester gathers everything publicly discoverable about the target: server names, software in use, employee names. After that, they search for known vulnerabilities, such as outdated software versions for which security updates have long existed. Surprisingly often, that alone is enough.

In the next step, they try to actually exploit a discovered gap. A classic example is an input field on a website that doesn’t properly check what the user enters. Instead of a name, the pentester types in a command that the database behind it executes. If that succeeds, they may be able to read out customer data. Once inside, they test how far they can spread through the network.

Not every attack is technical. In so-called social engineering, it’s not the technology that’s outwitted but the human being. The pentester calls the accounting department, pretends to be from the IT department, and asks for a password. At the end there is always a report: what was found, how serious it is, what needs to be fixed first. This report is the actual product, not the break-in itself.

Bug bounties, AI models, and the job market

Large corporations like Google or Apple pay rewards to anyone who reports a security vulnerability to them. These programs are called bug bounties. For critical vulnerabilities, six-figure sums are paid. Some pentesters work full-time as freelancers on such platforms, others are employed by specialized consulting firms.

Since the AI boom, a new field has emerged. Language models are also tested, but differently: attempts are made to get them, through cleverly worded prompts, to make statements they’re actually supposed to refuse. The term Red Teaming has become established for this. OpenAI, Anthropic, and Google maintain their own teams for this purpose and invite external testers before major releases.

In the news, this profession usually surfaces after an incident — then it’s reported that a security researcher discovered the vulnerability and reported it responsibly. A common misconception is that a passed pentest makes a system secure. It is always only a snapshot. After the next software update, the situation may already look different again.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.