For some reason I was looking for hackers to do some legal ethical hacking jobs.Someone recommended me this site <SNIP> they are hardcore hackers and I have heard good things about them,but the question is; how safe is to hire hackers?They will know everything about the network and it could be very risky, on the other side only a hackers can protect our network in that level which is actually desired.-

Dani AI

Generated

Short answer: it can be safe — but only with the right controls, contracts, and vendors. ’s instinct to get strong technical skill is correct, and the risk concerns raised by and are also valid: the difference between a useful ethical hacker and a legal/insider risk is process, not capability. Law and standards require explicit, written authorization and a defined rules-of-engagement before any active testing. (csrc.nist.gov)

Practical steps that make hiring safe: use accredited vendors or well‑documented methodologies; require a statement of work (SoW) and rules of engagement that list scope, allowed techniques, test windows, notification channels, and rollback plans; insist on NDAs, liability/insurance, and background checks where appropriate; and require secure handling and timely destruction of any credentials or sensitive data the tester obtains. Standards like PTES and NIST SP 800‑115 explain these pre‑engagement and engagement controls in detail. (pentesting.org)

If you prefer crowdsourced or phased approaches, managed bug‑bounty and crowdtesting platforms let you scale skill without handing blanket access to a single unknown individual — but they still require clear policies, triage resources, and initially small, controlled scopes. Well‑run programs and managed pentest providers document how reports, proofs‑of‑concept, and remediation are handled. (hackerone.com)

Quick checklist (use with any procurement):

  • Obtain signed, written authorization and an SoW before testing.
  • Prefer CREST‑accredited or otherwise vetted providers; check sample reports and references.
  • Build strict rules of engagement (scope, allowed exploits, test times, emergency contacts).
  • Use ephemeral/least‑privilege accounts, logging, and monitoring; require cleanup and credential destruction.
  • Require detailed technical + executive reports, remediation retest, NDA, and proof of insurance.

Following those steps reduces the “trust but verify” problem: hire the skill you need without transferring unacceptable legal or operational risk. (crest-approved.org)

Recommended Answers

All 3 Replies

I would not risk it. The major antivirus software companies won't employ a virus writer, so why risk your system ?

Denis

I would not risk it. The major antivirus software companies won't employ a virus writer, so why risk your system ?

Denis

As long as you can get along with them I think they are o.k.Real security only could be achieved by hackers.
In the very same way,- only a virus writer knows how to circumvent the anti-virus protection.

thread closed

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.