• Latest
  • Trending
Pentesting as a service: legal framework and contract design

Pentesting as a service: legal framework and contract design

28. February 2025
BGH considers Uber Black to be anti-competitive

Distance learning, coaching and synchronous online formats

2. March 2026
Media outlets consider influencers law pointless

Manipulated QR codes and quishing

27. February 2026
AI agents as autonomous contractual partners?

AI agents as autonomous contractual partners?

26. February 2026
Platform cooperatives as a financing and business model

AI training data as an asset: accounting, IP strategy and exit factor

25. February 2026
Streaming setup, influencers and contract law

Influencers: when marketing suddenly becomes commercial agency law

18. February 2026
Insolvency administrator and access to tax office data?

NRW audits influencers – and suddenly normal rules apply?

12. February 2026

Legal pitfalls in revenue-based financing for start-ups

12. February 2026
Streaming setup, influencers and contract law

Streaming setup, influencers and contract law

9. February 2026
Platform cooperatives as a financing and business model

Platform cooperatives as a financing and business model

8. February 2026
Frankfurt district court a.M. softens influencer jurisdiction

VAT on donations, gifts and “support” from influencers?

5. February 2026
Chamber Court on obligations to injuntture in the case of acts of third parties

Jurisdiction in the contract: one word too many, one word too few

4. February 2026
New info on the status of the State Media Treaty

Customer hotline and support in SaaS

2. February 2026
BGH considers Uber Black to be anti-competitive

BGH: FRAND objection fails due to lack of willingness to license

28. January 2026

InformationCheck.de is live: side project for source-based classification of social media claims

22. January 2026
DPMA

Paid mods, fan guidelines and EULA: when monetization is possible

21. January 2026
Is an 8 year old allowed to be an Esport player?

LOI, term sheet, MoU, often binding for startups?

20. January 2026
What actually is an IP? In the games, music and film industry!

Freelancer paid, but still not getting rights?

19. January 2026
Affiliate links for streamers and influencers

Comparison sites as an SEO trick

16. January 2026
Reverse vesting

Vesting, good leavers, bad leavers – why a lack of regulations costs startups dearly

15. January 2026

AI guideline for agencies and external service providers

14. January 2026
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Pentesting as a service: legal framework and contract design

28. February 2025
in Other
Reading Time: 6 mins read
0 0
A A
0

The demand for professional penetration tests (pentests for short) is growing steadily as companies place increasing importance on IT security. More and more companies are realizing that protecting sensitive data and systems is no longer just an option, but an indispensable part of a holistic corporate strategy. Pentesting service providers therefore play a crucial role in identifying potential vulnerabilities and proposing concrete measures to eliminate them. However, white-hat hackers or IT security consultants should not only view their activities from a technical perspective, but also create a solid legal basis to protect all parties involved from potential risks.

Content Hide
1. Legal basis of pentests
2. Drafting contracts for pentests
3. Regulations on documentation and rectification
4. Insurance cover and liability issues
5. Further aspects: Social engineering and compliance
6. Conclusion
6.1. Author: Marian Härtel
Key Facts
  • The demand for pentests is increasing, as IT security is crucial for corporate strategies.
  • Pentesting service providers identify vulnerabilities and suggest measures to rectify them.
  • A watertight contract is essential to minimize legal risks and clarify liability issues.
  • The GDPR requires the conclusion of a data processing agreement when processing personal data.
  • Pentests should be planned carefully, especially for hybrid infrastructures or cloud services.
  • Clear documentation and a rework phase are important to ensure the quality of the pentest.
  • Insurance cover and clear liability regulations are necessary to avoid economic risks.

In Germany, there is a whole range of legal standards that must be observed when carrying out pentests. Even minor violations can lead to serious consequences – for both the tester and the client. For this reason, a watertight contract is essential in order to regulate liability issues and create transparency regarding the exact scope of services. In addition to aspects such as limitations of liability and confidentiality obligations, topics such as data protection and compliance also play a central role. This ensures that the collaboration between service provider and client is built on a stable foundation from the outset.

In addition, the increasing complexity of modern IT systems requires careful planning of pentests. Tests often involve not only internal networks or web applications, but also hybrid infrastructures, cloud services or specialized industry-specific platforms. International standards such as ISO 27001 or the BSI IT baseline protection compendium provide points of reference here, and compliance with them is often even assumed by the client. Careful coordination with the client is therefore essential to ensure that all processes comply with legal requirements and company guidelines.

Legal basis of pentests

Penetration tests can essentially be understood as targeted checks of IT systems with the primary aim of uncovering security vulnerabilities. Pentesters slip into the role of potential attackers in order to identify both technical and organizational vulnerabilities. Companies that commission such tests want to minimize the risk of cyberattacks and increase the maturity of their security measures.

Despite being explicitly commissioned, the pentester’s actions can quickly fall into a legal gray area. Unauthorized intrusion into third-party systems is regulated in Germany in §§ 202a ff. of the German Criminal Code (StGB) and § 303b StGB. Even if the client has given their consent, this must be included in writing in the contract in order to avoid any subsequent ambiguities. A breach of these criminal provisions can have considerable consequences and may also trigger civil law claims for damages.

Another important point is data protection requirements. As soon as personal data is processed during testing activities, the GDPR applies. Article 28 GDPR stipulates that a data processing agreement (DPA) may need to be concluded in order to create the legal basis for data processing. This applies in particular if pentesters access data that allows conclusions to be drawn about natural persons, such as employee or customer data. Appropriate technical and organizational measures must be taken here to ensure that only the minimum necessary data is processed and that no sensitive information is collected without authorization.

Another legal hurdle is the potential disruption to ongoing business processes. If the attack simulations lead to system failures or data loss, this can quickly result in downtime that causes considerable economic damage. Such scenarios often lead to civil law disputes or insurance claims if the scope of liability and the question of possible negligence have not been contractually clarified. This makes it all the more important to precisely define the scope of the pentest and to clearly regulate in advance which measures are permitted and at what times they may be carried out.

Drafting contracts for pentests

A solid contract is the cornerstone of a legally compliant pentest implementation. Ideally, the collaboration should begin with a detailed agreement in which all parties involved clarify the objective of the pentest and which resources may be used. This prevents the tester from going beyond the agreed scope and inadvertently causing damage or accessing data that was not intended for the test.

Contracts should therefore precisely define which systems, networks or applications are to be tested. The type of test – such as a black box, white box or grey box approach – should also be specified. This not only has an impact on the tester’s approach, but also allows a more precise assessment of the time required and the potential risks. At the same time, details of the methodology or specific attack techniques (e.g. SQL injection, social engineering tests or automated tools) should be clarified so that the customer knows exactly which procedures will be used.

In addition, it is advisable to specify in the contract whether external service providers or subcontractors are involved. In larger projects in particular, the pentester may commission specialists for certain sub-areas. Here too, responsibilities should be clearly defined so that there are no legal loopholes. Ultimately, stringent planning and contractual stipulations facilitate the pentest and create trust among all parties involved.

Regulations on documentation and rectification

Most clients want to receive detailed documentation after completing a pentest in order to understand the weaknesses and potential risks found. A clearly structured report that not only lists the weaknesses but also sets priorities and makes specific recommendations for action is therefore essential. Ideally, this report should also be supplemented with management summaries so that decision-makers without in-depth IT knowledge can understand the results.

A rectification phase or a so-called “re-test” can also be part of the contract. Here, the pentesters check in a separate run whether the previously identified gaps have been closed or whether new weaknesses have arisen. It is important to set clear deadlines so that it is clear in which time window the improvements are to be carried out. This kind of structured documentation and rectification not only increases the quality of the pentest, but also achieves a sustainable security gain for the company.

Insurance cover and liability issues

Pentesting can have far-reaching consequences for the system integrity of a company. Particularly when sensitive systems are being tested, a failure can result in expensive production stoppages, contractual penalties or disgruntled customers. In such cases, it is advisable to take out professional indemnity insurance that covers such scenarios. A carefully drafted scope of insurance creates additional security for both parties and shows that the pentester is acting professionally and responsibly.

The contract should also clearly define the cases in which liability for damages is excluded or limited. A typical formulation is the limitation of liability to intentional or grossly negligent acts. The question of whether consequential damages or loss of profit are recoverable should also be clarified in advance. Such regulations avoid disputes and enable a fair distribution of risk. Ideally, internal escalation levels should also be defined so that disagreements can be resolved before a legal dispute arises.

Further aspects: Social engineering and compliance

One area that often gains importance in pentest contracts is social engineering. This is where testers attempt to obtain information from employees through phishing emails, fake calls or fake websites in order to penetrate company networks. While such tests are often very effective in checking the human element in security concepts, they can also be legally tricky if the consent of the employees or works councils concerned is not obtained. Clearly defined procedures and limits should therefore also be set out in the contract for social engineering tests.

The topic of compliance also plays a major role in many industries. Certain sectors, such as banking, insurance or healthcare, are subject to strict regulations regarding the handling of data or the type of security checks carried out. Here, it is important to determine in advance which standards and guidelines apply and how the pentest can be tailored to them. Close coordination with the client and its specialist departments ensures that the pentest does not violate internal or external rules and that the results can be used for future audits or certifications.

Conclusion

The legally compliant implementation of pentests requires a well thought-out concept, careful coordination with the client and a seamless contract design. Starting with the selection of suitable test methods and the definition of liability limits through to data protection issues, all points should be set out in clear agreements. Precise preparation prevents misunderstandings and creates the basis for successful collaboration.

It is particularly important that both parties define in advance exactly what goals are to be achieved with the test and what risks they wish to take. Good communication and transparency are essential to ensure that neither the company nor the pentester experience any unpleasant surprises. Especially in a highly dynamic environment such as IT security, it is advantageous to rely on the expertise of a lawyer who is familiar with the technical and legal particularities.

As a specialist in IT law and a passionate technology enthusiast, I can help draft contracts in such a way that they both meet the client’s requirements and are legally watertight. In this way, cyber risks are minimized and trust between all parties involved is strengthened. With my in-depth understanding of security processes and my legal advice, pentests can be carried out not only effectively but also in a legally compliant manner. The result is optimized IT structures, an improved security culture and the certainty of being protected from unforeseeable consequences in the event of an emergency.

 

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Weitere spannende Blogposts

YouTube is only liable for infringements if there is a clear indication of infringement

YouTube: What to do about copyright extortion?
11. September 2023

Introduction: In a landmark decision, the Hamburg Higher Regional Court has specified the requirements for YouTube's liability for copyright infringement....

Read moreDetails

Legal aspects of digital twins: data ownership and liability in virtual replications

Legal aspects of digital twins: data ownership and liability in virtual replications
21. October 2024

Digital twin technology is revolutionizing numerous industries, from product development and asset management to urban planning. These virtual replications of...

Read moreDetails

Tax liability for “Play to Earn” games

Tax liability for “Play to Earn” games
5. December 2022

Introduction From the first game console in 1972 to millions of games on the smartphone, a lot has changed in...

Read moreDetails

Protecting business ideas and business concepts: Possibilities and limits

Protecting business ideas and business concepts: Possibilities and limits
2. January 2025

Time and again, clients ask whether and how they can legally protect their business idea or business concept. This is...

Read moreDetails

ECJ rules on the right to be forgotten

Lego brick still protected as a design patent
8. December 2022

Following the Federal Constitutional Court, the ECJ has now also ruled on the right to be forgotten in search engines....

Read moreDetails

Lupedi UG: Warning notice received?

Online retailer: Notice of warranty of defects
7. November 2022

In recent months, Lupedi UG, represented by the law firm Bleischwitz & Schierer, has been issuing warnings to Ebay users,...

Read moreDetails

Preparing for Brexit?

Preparing for Brexit?
10. October 2019

Even if you never know for sure, it looks as if the UK will leave the European Union on 1...

Read moreDetails

English version (of the homepage) complete

English version (of the homepage) complete
28. December 2022

I still have to tinker around for a while to fix some small bugs with the english version of the...

Read moreDetails

Telephone number in revocation instruction

Online shops: Attention to advertising with EIA
25. January 2019

The Schleswig-Holstein Higher Regional Court has strengthened the rights of consumers in a decision issued. The defendant distributes telecommunications services,...

Read moreDetails
BGH considers Uber Black to be anti-competitive
Law and Esport

Distance learning, coaching and synchronous online formats

2. March 2026

The Distance Learning Protection Act (FernUSG) has been experiencing a renaissance for some time now. What for decades was considered...

Read moreDetails
Media outlets consider influencers law pointless

Manipulated QR codes and quishing

27. February 2026
AI agents as autonomous contractual partners?

AI agents as autonomous contractual partners?

26. February 2026
Platform cooperatives as a financing and business model

AI training data as an asset: accounting, IP strategy and exit factor

25. February 2026
Streaming setup, influencers and contract law

Influencers: when marketing suddenly becomes commercial agency law

18. February 2026

Podcastfolge

Looking to the future: How technology is changing the law

Looking to the future: How technology is changing the law

18. February 2025

In the final episode of the first season of the ITmedialaw.com podcast, we take a look at the future of...

Read moreDetails

Smart contracts and blockchain

15. January 2025

The IT Media Law Podcast. Episode No. 1: What is this actually about?

26. August 2024

AI in the legal system: Towards a digital future of justice

16. October 2024

Digital sovereignty: Europe’s path to a self-determined digital future

8. December 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung