A contract
Two identified companies, an object, a term and an invoice. Without a contract there is no service: there is a shared problem.
If you got here looking for how to hire a hacker, this is the version that is legal: an ethical hacker who attacks your systems with your written permission and tells you how they got in, before somebody else does it without asking.
The technical name is a penetration test. Senior ethical hackers do it by hand, and it ends in a report with evidence for every finding and a retest to check that what you fixed is actually fixed.
How to startProtected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
The person who would run the test will reply within one business day.
No se ha podido enviar. Inténtalo otra vez o escríbenos.
Answered here, in one line each, with the long version further down the page.















Start with the uncomfortable part: the techniques are the same. Somebody who breaks into a system to rob you and somebody who breaks in to show you how it is done use the same tools and the same knowledge. The difference is not the technique. It is the authorisation.
Spanish criminal law puts it in article 197 bis of the Código Penal, which punishes with six months to two years in prison anybody who, by any means, breaching the security measures put in place to prevent it, and without being duly authorised, accesses or gives another person access to all or part of an information system. The line is drawn by the law itself, and it is drawn at the authorisation, not at the skill of whoever gets in.
Two more articles are worth knowing, because they cover the requests that reach an inbox like ours and cannot be accepted. Article 197.1 punishes seizing somebody else's messages or intercepting their communications without consent, which is what "get into an employee's email" means. And article 264.1 punishes deleting or damaging somebody else's data without authorisation, which is what "take that site down" means.
We are not lawyers and this is not legal advice. We say it because it is the question almost nobody asks out loud, and it deserves a clear answer before anybody spends a euro.
Two identified companies, an object, a term and an invoice. Without a contract there is no service: there is a shared problem.
Which systems get touched, which do not, from when until when, and with what intensity. The scope is what turns "get into a system" into "get into this system, with permission, this far".
The owner of the system. If a third party hosts your site or runs your ERP, their permission is needed too. It is not bureaucracy: it is what separates an authorised test from unlawful access with your signature behind it.
Confidentiality in writing, an agreed procedure for when something serious turns up mid-engagement, and somebody with a name to hold responsible. An offence has no after-sales service.
You do not have to be technical. Whoever is going to do the job properly asks you for uncomfortable things before charging you: proof that you own what you want tested, a signed scope, written authorisation. Whoever asks for none of that, gives you no contract and no invoice, or offers to get into something that is not yours, is telling you what they are.
These are real requests. None of them can be accepted, and in almost all of them there is something legitimate that can be done instead.
"Get my Instagram or WhatsApp account back."
No. That goes through the platform's support and, if there is an offence behind it, through a police report. Anybody promising to recover it by breaking into it is not going to do it legally.
"Get into this person's phone, email or WhatsApp."
No, and that is article 197.1. It makes no difference whether it is your partner, your business partner or an employee: the person who authorises is the account holder.
"Have a look at what the competition has."
No. Their systems are not yours and you cannot authorise a test on them.
"I have been scammed, hack the scammer."
No. What does exist: preserving the evidence and reconstructing what happened with digital forensics, so that the police report stands up.
"Delete what they published about me" or "take that site down".
No, and that is article 264.1. What does exist: watching what is exposed about your company and your credentials, and handling takedowns through the channels that exist for it.
"Test this system for me, even though it is not mine."
Not without written authorisation from its owner. If it is your supplier, ask them: many already have a procedure for giving it.
And one that is not illegal but is not a penetration test either: "tell me whether I have already been hacked". A pentest looks for how somebody would get in, not whether somebody already did. That is a different job, and if you have reason to think it has happened, do not wait for the pentest to call.
What is in, what is out, when, and who to call if something breaks. In writing and signed by both sides.
Scanners run too, but they are the starting point. Business logic flaws, broken authorisation and chained exploits are found by a person.
Every finding with the steps to reproduce it, the evidence it worked and what it would take to fix it, ordered by what matters to your business. Plus a live readout session with your technical team.
Once you have fixed things, we test the same findings again. A vulnerability is not closed because a ticket says so.
This is also what tells a penetration test apart from a vulnerability scan. A scanner hands you a list of what could be exploitable, ordered by a score. A penetration test proves what is, in your environment, with your data and your permissions, and says how far it goes.
Ethical hacking is the label; a penetration test, or pentest, is the job. What changes from one engagement to the next is what gets attacked.
The services are named after the attack vector, and the vector is jargon. Look for the sentence closest to what you would actually say.
If your answer is "several of these", that is normal and you do not have to choose today: we scope the ones that matter and order them by where the risk is, not by catalogue.
The scope is half the job and it is where a hiring goes wrong. The more specific it is, the less time goes into preparation and the more into testing. Worth having to hand before the first call:
What stays out by default, unless it is contracted on purpose: no denial of service testing, no social engineering against your staff (that is a phishing simulation, with its own scope and its own consent) and no third-party systems without their owner's authorisation.
On duration and price, because it is the first thing anybody asks: both come out of the scope and both go in the proposal in writing before anybody touches anything. There is no flat rate because there are no two identical scopes.
A customer or an insurer is asking for a penetration test report before they sign.
You are shipping something new, and nobody outside the team has tried to break it.
An audit, a certification or a regulation asks for evidence that somebody tested it.
Something already happened, and you want to know what else is open.
Three steps, and you can do the first one right now.
Make the list
What you want tested and who owns each thing. With that we can already talk about scope.
Tell us what worries you
In your own words. You do not need to know whether it is an external or an internal test: that is what the first call is for.
You get a proposal
With scope, duration and objectives. Nobody touches anything before you sign it.
And if what you need is not this, we will say so. It is cheaper for both of us than a project that does not answer your question.
There is a point where the question changes. A penetration test answers "how does somebody get into this?". A red team answers "would we notice, and how long would it take us to throw them out?".
That only makes sense if you already have something to detect with: people watching alerts, response procedures, tools deployed. If you do not have that yet, a red team will prove something you already know and cost you more. In that case the penetration test pays better first.
Senior ethical hackers. Our team holds OSCP, OSCE³, OSWE, OSEP, CRTO and CRTP credentials, which are practical exams: you have to get the access inside a lab and write the report, not tick the right answer.
Even so, do not go on the acronyms alone. Ask any supplier for an anonymised sample report and look at whether it proves what it says or just lists what a scanner found.
Companies that hired offensive testing and renewed.
We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
If what you need is not this, these are the other families of work.
Is it legal to hire a hacker?
It is legal to hire an ethical hacker to test systems you own or are entitled to authorise. It is not legal to hire anybody to get into a system that is not yours, whoever they say they are. Article 197 bis of the Spanish Código Penal puts the line at the authorisation.
What is an ethical hacker, exactly?
A professional who assesses the security of systems, networks and applications using the same techniques an attacker would, with the prior written authorisation of the owner, within an agreed scope, and under an obligation to report everything they find and use it for nothing else. All three parts count: without authorisation it is an offence, without a scope it is not a service, and without the obligation to report it is not an audit.
Is this the same as a penetration test?
Yes. Ethical hacking is the general term and a penetration test is the engagement: an agreed scope, a time window, manual testing and a report.
What does it cost to hire an ethical hacker?
It depends on the scope, which is why there is no rate on this page. What moves the price is how many targets there are, how deeply they are tested, whether there are users and roles to walk through, whether on-site work is needed and whether it is tested in production. What you can expect is a closed proposal with scope, duration and objectives before anybody touches a system, with the retest included in it.
What do you need from us to start?
Somebody who can authorise the test, a list of what is in scope, and a window. Everything else we work out in the kick-off.
Do the systems have to be taken down?
Normally not. A window is agreed, anything that could degrade the service is avoided and, if a test carries that risk, you are told beforehand and it is decided with you. Denial of service testing is not part of a penetration test unless it is contracted separately.
And if you find something serious mid-engagement?
We stop and tell you the same day, through the channel agreed in the rules of engagement. A critical finding does not wait for the final report.
Send us the scope, or a rough idea of it, and we will tell you what kind of test fits and what it would involve.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
We will reply within one business day with what kind of test fits and what it would take to scope it.
No se ha podido enviar. Inténtalo otra vez o escríbenos.
If what you need is not this, these are the other families of work.
See every servicePick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.