• Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Kurzberatung
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Pentesting as a service: legal framework and contract design

28. February 2025
in Other
Reading Time: 6 mins read
0 0
A A
0
fc928a67 a526 4972 ac72 a769e4d69bb5 15307134
Key Facts
  • The demand for pentests is increasing, as IT security is crucial for corporate strategies.
  • Pentesting service providers identify vulnerabilities and suggest measures to rectify them.
  • A watertight contract is essential to minimize legal risks and clarify liability issues.
  • The GDPR requires the conclusion of a data processing agreement when processing personal data.
  • Pentests should be planned carefully, especially for hybrid infrastructures or cloud services.
  • Clear documentation and a rework phase are important to ensure the quality of the pentest.
  • Insurance cover and clear liability regulations are necessary to avoid economic risks.

The demand for professional penetration tests (pentests for short) is growing steadily as companies place increasing importance on IT security. More and more companies are realizing that protecting sensitive data and systems is no longer just an option, but an indispensable part of a holistic corporate strategy. Pentesting service providers therefore play a crucial role in identifying potential vulnerabilities and proposing concrete measures to eliminate them. However, white-hat hackers or IT security consultants should not only view their activities from a technical perspective, but also create a solid legal basis to protect all parties involved from potential risks.

Content Hide
1. Legal basis of pentests
2. Drafting contracts for pentests
3. Regulations on documentation and rectification
4. Insurance cover and liability issues
5. Further aspects: Social engineering and compliance
6. Conclusion
6.1. Author: Marian Härtel

In Germany, there is a whole range of legal standards that must be observed when carrying out pentests. Even minor violations can lead to serious consequences – for both the tester and the client. For this reason, a watertight contract is essential in order to regulate liability issues and create transparency regarding the exact scope of services. In addition to aspects such as limitations of liability and confidentiality obligations, topics such as data protection and compliance also play a central role. This ensures that the collaboration between service provider and client is built on a stable foundation from the outset.

In addition, the increasing complexity of modern IT systems requires careful planning of pentests. Tests often involve not only internal networks or web applications, but also hybrid infrastructures, cloud services or specialized industry-specific platforms. International standards such as ISO 27001 or the BSI IT baseline protection compendium provide points of reference here, and compliance with them is often even assumed by the client. Careful coordination with the client is therefore essential to ensure that all processes comply with legal requirements and company guidelines.

Legal basis of pentests

Penetration tests can essentially be understood as targeted checks of IT systems with the primary aim of uncovering security vulnerabilities. Pentesters slip into the role of potential attackers in order to identify both technical and organizational vulnerabilities. Companies that commission such tests want to minimize the risk of cyberattacks and increase the maturity of their security measures.

Despite being explicitly commissioned, the pentester’s actions can quickly fall into a legal gray area. Unauthorized intrusion into third-party systems is regulated in Germany in §§ 202a ff. of the German Criminal Code (StGB) and § 303b StGB. Even if the client has given their consent, this must be included in writing in the contract in order to avoid any subsequent ambiguities. A breach of these criminal provisions can have considerable consequences and may also trigger civil law claims for damages.

Another important point is data protection requirements. As soon as personal data is processed during testing activities, the GDPR applies. Article 28 GDPR stipulates that a data processing agreement (DPA) may need to be concluded in order to create the legal basis for data processing. This applies in particular if pentesters access data that allows conclusions to be drawn about natural persons, such as employee or customer data. Appropriate technical and organizational measures must be taken here to ensure that only the minimum necessary data is processed and that no sensitive information is collected without authorization.

Another legal hurdle is the potential disruption to ongoing business processes. If the attack simulations lead to system failures or data loss, this can quickly result in downtime that causes considerable economic damage. Such scenarios often lead to civil law disputes or insurance claims if the scope of liability and the question of possible negligence have not been contractually clarified. This makes it all the more important to precisely define the scope of the pentest and to clearly regulate in advance which measures are permitted and at what times they may be carried out.

Drafting contracts for pentests

A solid contract is the cornerstone of a legally compliant pentest implementation. Ideally, the collaboration should begin with a detailed agreement in which all parties involved clarify the objective of the pentest and which resources may be used. This prevents the tester from going beyond the agreed scope and inadvertently causing damage or accessing data that was not intended for the test.

Contracts should therefore precisely define which systems, networks or applications are to be tested. The type of test – such as a black box, white box or grey box approach – should also be specified. This not only has an impact on the tester’s approach, but also allows a more precise assessment of the time required and the potential risks. At the same time, details of the methodology or specific attack techniques (e.g. SQL injection, social engineering tests or automated tools) should be clarified so that the customer knows exactly which procedures will be used.

In addition, it is advisable to specify in the contract whether external service providers or subcontractors are involved. In larger projects in particular, the pentester may commission specialists for certain sub-areas. Here too, responsibilities should be clearly defined so that there are no legal loopholes. Ultimately, stringent planning and contractual stipulations facilitate the pentest and create trust among all parties involved.

Regulations on documentation and rectification

Most clients want to receive detailed documentation after completing a pentest in order to understand the weaknesses and potential risks found. A clearly structured report that not only lists the weaknesses but also sets priorities and makes specific recommendations for action is therefore essential. Ideally, this report should also be supplemented with management summaries so that decision-makers without in-depth IT knowledge can understand the results.

A rectification phase or a so-called “re-test” can also be part of the contract. Here, the pentesters check in a separate run whether the previously identified gaps have been closed or whether new weaknesses have arisen. It is important to set clear deadlines so that it is clear in which time window the improvements are to be carried out. This kind of structured documentation and rectification not only increases the quality of the pentest, but also achieves a sustainable security gain for the company.

Insurance cover and liability issues

Pentesting can have far-reaching consequences for the system integrity of a company. Particularly when sensitive systems are being tested, a failure can result in expensive production stoppages, contractual penalties or disgruntled customers. In such cases, it is advisable to take out professional indemnity insurance that covers such scenarios. A carefully drafted scope of insurance creates additional security for both parties and shows that the pentester is acting professionally and responsibly.

The contract should also clearly define the cases in which liability for damages is excluded or limited. A typical formulation is the limitation of liability to intentional or grossly negligent acts. The question of whether consequential damages or loss of profit are recoverable should also be clarified in advance. Such regulations avoid disputes and enable a fair distribution of risk. Ideally, internal escalation levels should also be defined so that disagreements can be resolved before a legal dispute arises.

Further aspects: Social engineering and compliance

One area that often gains importance in pentest contracts is social engineering. This is where testers attempt to obtain information from employees through phishing emails, fake calls or fake websites in order to penetrate company networks. While such tests are often very effective in checking the human element in security concepts, they can also be legally tricky if the consent of the employees or works councils concerned is not obtained. Clearly defined procedures and limits should therefore also be set out in the contract for social engineering tests.

The topic of compliance also plays a major role in many industries. Certain sectors, such as banking, insurance or healthcare, are subject to strict regulations regarding the handling of data or the type of security checks carried out. Here, it is important to determine in advance which standards and guidelines apply and how the pentest can be tailored to them. Close coordination with the client and its specialist departments ensures that the pentest does not violate internal or external rules and that the results can be used for future audits or certifications.

Conclusion

The legally compliant implementation of pentests requires a well thought-out concept, careful coordination with the client and a seamless contract design. Starting with the selection of suitable test methods and the definition of liability limits through to data protection issues, all points should be set out in clear agreements. Precise preparation prevents misunderstandings and creates the basis for successful collaboration.

It is particularly important that both parties define in advance exactly what goals are to be achieved with the test and what risks they wish to take. Good communication and transparency are essential to ensure that neither the company nor the pentester experience any unpleasant surprises. Especially in a highly dynamic environment such as IT security, it is advantageous to rely on the expertise of a lawyer who is familiar with the technical and legal particularities.

As a specialist in IT law and a passionate technology enthusiast, I can help draft contracts in such a way that they both meet the client’s requirements and are legally watertight. In this way, cyber risks are minimized and trust between all parties involved is strengthened. With my in-depth understanding of security processes and my legal advice, pentests can be carried out not only effectively but also in a legally compliant manner. The result is optimized IT structures, an improved security culture and the certainty of being protected from unforeseeable consequences in the event of an emergency.

 

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Weitere spannende Blogposts

Attention: Insufficient cookie banners soon in the sights of data protectionists

ECJ: Cookies require explicit consent of users
7. November 2022

After the German data protection authorities published a guidance document last year, the Planet49 case should now be known to...

Read moreDetails

Agencies: Attention, ideas not protected!

Agencies: Attention, ideas not protected!
31. May 2019

For this reason, I would like to draw attention today to a problem that repeatedly falls on the feet of...

Read moreDetails

Flash scaling and aggressive business models: Innovation between progress and evasion

Flash scaling and aggressive business models: Innovation between progress and evasion
4. April 2025

Digitalization has given rise to a new generation of business models that are growing at a rapid pace and revolutionizing...

Read moreDetails

Killer games and constitutional law *Update

Killer games and constitutional law *Update
7. November 2022

Since I was asked about it. Both the political and legal situation is completely different from what it was 12...

Read moreDetails

Secret teacher videos on Instagram? Suspension from school!

Secret teacher videos on Instagram? Suspension from school!
7. November 2022

The Administrative Court of Berlin has ruled in two summary proceedings that two students in a tenth grade class of...

Read moreDetails

EU directive on the right to repair

Privacy policy
18. June 2024

On April 23, 2024, the EU Parliament adopted a groundbreaking directive to strengthen the right to repair in the European...

Read moreDetails

Office 365 in schools illegal under data protection law

Office 365 in schools illegal under data protection law
7. November 2022

1. preliminary remark For years, there has been a debate in Germany about whether schools can use Microsoft's Office 365...

Read moreDetails

Fack ju Göthe may be registered as a trademark

International trademark application at WIPO
7. November 2022

One believes to have had many problems in trademark law at least once on the table or to have evaluated...

Read moreDetails

Startup buzzwords 2025: Bullshit bingo in marketing German Introduction: Bullshit bingo in marketing German

Startup buzzwords 2025: Bullshit bingo in marketing German Introduction: Bullshit bingo in marketing German
18. May 2025

The startup scene of 2025 is teeming with trendy startup jargon - a feast for every bullshit bingo. Whether on...

Read moreDetails
Contractual regulations for no-code/low-code software development
Other

Contractual regulations for no-code/low-code software development

21. May 2025

No-code and low-code platforms enable rapid software development without extensive manual programming. Applications are increasingly being developed on the basis...

Read moreDetails
Erotic content on OnlyFans: Copyright and personality rights protection for creators

Erotic content on OnlyFans: Copyright and personality rights protection for creators

20. May 2025
Goodbye hustle culture? Startup life between 24/7 grind and work-life balance

Goodbye hustle culture? Startup life between 24/7 grind and work-life balance

19. May 2025
Startup buzzwords 2025: Bullshit bingo in marketing German Introduction: Bullshit bingo in marketing German

Startup buzzwords 2025: Bullshit bingo in marketing German Introduction: Bullshit bingo in marketing German

18. May 2025
From the metaverse boom to AI euphoria – a tech lawyer in the hype cycle

From the metaverse boom to AI euphoria – a tech lawyer in the hype cycle

17. May 2025

Podcastfolge

d00527fd01b1f807a4f80c0f202069e7

Legal basics for startup founders – how to start on the safe side!

9. November 2024

In this episode of the Itmedialaw podcast, lawyer and entrepreneur Marian Härtel takes you on a journey through the legal...

Read moreDetails
AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

24. September 2024
247f58c28882e230e982fa3a32d34dea

Digital sovereignty: Europe’s path to a self-determined digital future

8. December 2024
da884f9e2769f2f96d6b74255be62c27

The role of the IT lawyer

5. September 2024
d5ab3414c7c4a7a5040c3c3c60451c44

The metaverse – legal challenges in virtual worlds

26. September 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung