Ethical hackers and red teams: what a penetration test reveals about your business

Published on August 24, 20267 min read
An authorised ethical security tester, wearing a visible access pass, probes a company's digital lock with permission to find weak points

One morning, an important client asks Sophie B. a simple question: “If a hacker went after your firm, would you hold up?” Sophie handles the books and payroll of hundreds of small businesses. She has antivirus software, passwords, and an external provider who “takes care of IT.” But no one has ever actually tried to force the door open — so she doesn't know what to answer. That is exactly the question a penetration test is designed to answer.

The penetration test: letting an ally in before the intruder

Let's start with the words, because they scare people for nothing. An ethical hacker is a specialist you hire to attack your own systems — with your written consent — for one purpose only: to find the weaknesses before real attackers do. When several of these specialists work as a team to replay a realistic, end-to-end attack, we call it a red team (the “red” side plays the attacker, as opposed to the “blue” side that defends). And the exercise itself — a controlled, authorised simulated attack — is called a penetration test, often shortened to pentest.

The accurate picture is not the movie hacker in a hoodie surrounded by green code. It is closer to a locksmith you pay to try to break into your own building: they test the doors, the windows, the garage door everyone forgets, and hand you a list of what gave way. At no point do they burgle — they document. The value is not in the “attack”; it is in the report that follows.

People often confuse a penetration test with a simple automated scan — the software that reviews your system and spits out a list of alerts. A scan is useful, but it only flags possible doors. The ethical hacker actually tries to open them and see how far they lead: that is the difference between a list of theoretical risks and proof of what an attacker would really obtain.

Why is a firm like Sophie B.'s concerned? Because it ticks every box of an attractive target: highly sensitive data — accounts, salaries, tax details of many clients —, a reputation for trust that is its core business, and no in-house IT person to keep watch. An attacker isn't necessarily hunting for the large enterprise; they look for the easiest door that leads to data worth money. A service SME is often exactly that.

What a test brings to light isn't technical wizardry: it's the small, everyday things that, stacked together, open a path. A remote access left on since a spell of home working. A password shared between three people and never changed. An employee who clicks a fake email from the tax office — not out of foolishness, but because it looked exactly like a real one. A backup that exists on paper but that no one has ever tried to restore. The specialist connects these little nothings and shows, concretely, how far they could have gone. Then they leave, without having taken anything.

In practice, a mission always follows the same stages. First, we agree together on the scope and the authorisations. The specialist then observes what is visible about your company, just as a real attacker preparing their move would. Within the agreed limits, they try to exploit the weaknesses found — not to cause harm, but to prove they are real. They log everything, then report back: a summary for management, a detailed list for those who fix things, and an order of priority. The real work starts there, when you repair what has been shown.

Key takeaways

A penetration test measures reality, not intentions. You can have antivirus software, an IT policy and the best will in the world: until someone has tried to get through, you don't know whether your protections hold. The exercise replaces “I think we're protected” with “here is exactly what holds and what gives way.”

The deliverable is the report — not the break-in. A good ethical hacker leaves you a prioritised list: what is serious and must be fixed immediately, what can wait, and how to go about it. That document is what has value, not the demonstration.

Finally, you don't need to be a multinational, nor to start with a full test. A proper pentest is an investment that has to be prepared, and it only makes sense once the basics are in place: no point paying a specialist to discover that multi-factor authentication is missing — you already know that. Before you get there, you can make huge progress simply by knowing what, at your firm, is exposed — and that costs nothing.

Steps to put in place this week

1. Never let anyone test without written authorisation

The first step is also the most counter-intuitive: before any attempt, you write down in black and white what may be tested, when, and how the data will be handled. This is what we call the “rules of engagement.” Without that framework, a test becomes illegal at best and dangerous at worst. This document also protects you under the nFADP — the revised Swiss data protection act, in force since 2023, which makes you responsible for the data you hold. If you ever engage a specialist, insist on this framework before they touch anything.

2. Map your “exposed surface”

You don't need an expert to start: list everything that, from the internet, lets someone into your business. The login page for your Microsoft 365 mailbox, a remote access for home working, the firm's website, a file-sharing space with clients. Ask your provider for this list if they hold it. Knowing what is visible from the outside is already the first penetration test — the one you run yourself, without spending a franc. The Swiss federal office for cybersecurity (NCSC) publishes free recommendations for SMEs on exactly these points.

3. Ask your provider the questions a pentester would ask

An ethical hacker almost always starts with the same weak points; you can check them without one. Is multi-factor authentication — a second code, on top of the password, for example on your phone — active everywhere, and not just on management's mailbox? Have our backups actually been tested by a real restore, or only “run”? Who keeps access to our files after leaving the firm? Three questions, three honest answers: you'll already have the essence of what a test charges a great deal to reveal.

Where do you really stand?

A full penetration test answers the question put to Sophie B. in the most honest way there is. But before committing a budget, it is often more useful to know where you stand, item by item: access, backups, awareness, handling of departures. That is exactly what a self-assessment structures.

Cyber Passport certifies nothing and does not declare you “secure” — no serious player would. The platform acts as the auditor: it shows you, question after question, where your organisation is solid and where it rests mostly on trust and habit. It is the best starting point before inviting an ethical hacker to try, for real, to open the door.

Topics

  • penetration test
  • ethical hacking
  • red team
  • SME
  • Switzerland

Read next