Career Paper

Penetration Testing

William Gardin

School of Cybersecurity, Old Dominion University CYSE

201S: Cybersecurity and the Social Sciences

4/16/25

Introduction

Penetration testing is a crucial career in the cybersecurity field. Penetration testing deals with protecting critical infrastructure in various industries. They protect critical infrastructure by testing its cybersecurity systems for any type of flaws that a cybercriminal might exploit. As cybercriminals become more sophisticated with their cyber-attacks, corporations and business owners are relying more on penetration testers to test their cybersecurity for any weaknesses. While penetration testers are doing their job, they are using various concepts from social sciences to make their job as efficient and effective as possible. Even though this career has an overly positive effect for society, it still can have negative effects for certain marginalized groups. In this paper I will explain how penetration testers use social science principles, key concepts from class, the relationship between the career and marginalized groups, and its connection to society,

Social Science Principles

              Penetration testers use various types of social science principles while they are doing their job. One principle that they use is parsimony. After penetration testers are finished with their testing, they analyze their results and report them to their client. When they report their results to their client, they need to be able to communicate their results as simple as they can so that their client can fully understand their weaknesses in their cybersecurity systems and deal with them accordingly. Another principle that penetration testers use is objectivity. When penetration testers are doing their job, they need to do it in an unbiased manner. This helps with making sure their testing is to the best of their efforts, which will be seen in the results. When communicating these results to their client, they need to do that in an unbiased manner so that the clients can get an understanding of what they truly need to do. If a penetration tester was biased, it could affect their results, which could leave out some weaknesses that might hurt their clients in the future. Relativism is also a social science principle that penetration testers use. When penetration testers are testing a cybersecurity system, they need to be able to find out what is causing something to be a weakness in a system. This will help with communicating the cause of the issue to their client.

Key concepts relating to penetration testing

              Cost/benefit analysis is one concept that we learned in class that can apply to penetration testing. Cost/benefit analysis is an approach that people use when evaluating the strengths and weakness of something, and in the end deciding whether or not it is worth the cost.  In penetration testing, one strength would be that they help with finding weaknesses in critical infrastructure, and one weakness is that they typically ask for more money than a bug bounty hunter would. Depending on how the client feels about those strengths and weaknesses will influence their decision on whether or not it is worth paying for a penetration tester. Another concept that can be applied to penetration testing is social engineering. Social engineering are tactics that cybercriminals use to make more sophisticated cyber-attacks. One social engineering technique cybercriminals use is phishing. Phishing is when someone sends their victim a message via email posing as a reputable person. When they do this, they are trying to seek out valuable information from their victim that they can sell to someone or use to commit even more cybercrimes. For a penetration tester, their job is to help with preventing social engineering. They need to think about how a cybercriminal would break into a system and mimic it. This will help them with identifying any weaknesses that there could be within their client’s cybersecurity system. Mitigation is also a concept that can be applied to penetration testing. When a penetration tester is doing their job, they are helping with mitigating the effects of a potential cyber-attack on a system by looking for weaknesses and fixing them before they become a problem for client in the future. Communication is a crucial concept that applies to penetration testing. The tester needs to be able to communicate to their clients any type of weaknesses that they were able to find in their testing as effectively as possible. If the tester does not know how to communicate their results well, it could lead to lots of confusion for their client.

Marginalization

Even though penetration testing can bring a lot of positives in the cybersecurity field, they also bring negative effects to a certain group. The group that has to deal with these negative effects are people whose data is in the hands of penetration testers. Louis McDonald’s article “Ethical Challenges of Penetration Testers” and Anup Mistry’s article “A New Approach of Uncovering Hidden Risks with Internal Threat Testing” both dive into this topic and explains the connections and motives. In McDonald’s article, he points out that this group could be negatively affected by “Exploitation of privileged access by insiders with malicious intent (McDonald)”. Since a penetration tester is given exclusive access, they can end up exploiting this access to potentially steal peoples sensitive information within a database. In Mistry’s article she talks about motives penetration testers could have when they do this. She says that the malicious actors are usually “employees or ex-employees (Mistry et al.)”. This could point towards a problem that when penetration testers are working with a client, they are being mistreated, causing them to retaliate by becoming an insider threat. This issue can also give way to other challenges. One challenge that arises from this is how companies can prevent this from happening. If companies overlook this problem, it could lead to more penetration testers becoming insider threats and stealing people’s data for profit. Another challenge that arises from penetration testing exploitation is overall trust with penetration testers. If a majority of penetration testers ended up using their access to customer’s data in a malicious manner, this can result in trust being lost from companies, which will result in penetration tester jobs fading away from the cybersecurity field. This will end up removing resources that companies will have to protect their customer’s data, which will increase the risk of their data being stolen. An increase in the number of cybercriminals will also happen if this problem were to gain popularity. If cybercriminals see that penetration testers are exploiting their access to maliciously take customer data, they might see it as a chance to either start committing even more cyber-attacks of their own or recruit those penetration testers to their side.

Connection to society

Penetration testers are crucial when it comes to society.  One relationship that penetration testing has with society is that it provides a form of protection to critical infrastructure that has people’s sensitive information on it. Papa Orleans-Bosomtwe from Cornell University dives further into this relationship. He says that penetration testing is an essential for “Identifying and addressing security weakness, allowing the organization to fortify their defenses (Orleans-Bosomtwe, Papa Kobina). With penetration testers improving a company’s cyber defenses, the customer’s of that company would not have to worry about their account information or credit/debit card information being compromised. Building customer trust is another way penetration testers connect to society. With penetration testers protecting their information, it builds a level of trust with the customers. It reassures them that their information is secure and protected. Job growth is another relationship penetration testers and society share. With companies looking for ways to keep their cybersecurity systems up to date from cybercriminals, it increases the demand for jobs like penetration testers.

Conclusion

Penetration testers are crucial for the cybersecurity field. By applying parsimony, objectivity, and relativism, penetration testers are able to communicate their results to their clients better and do their job better. When penetration testers are doing their job, they have to consider various types of concepts that were taught in class, such as cost/benefit analysis, social engineering, mitigation, and communication. Even though penetration testing comes with a vast number of positive impacts like protecting critical infrastructure, building a level of trust with customers, and creating more jobs, it also causes ethical challenges to come to light like insider threats, how companies can defend themselves from insider threats, and an increase of cybercriminals. As cybercriminals become more sophisticated with their cyber-attacks, the more penetration testers will be needed to counter them.

Sources

McDonald, Louis . “Ethical Challenges of Penetration Testers – ProQuest.” Proquest.com, 2024, www.proquest.com/openview/57b30a9ae6f502cbe3e3a6f4cd129165/1?cbl=18750&diss=y&loginDisplay=true&pq-origsite=gscholar. Accessed 16 Apr. 2025.

Mistry, Anup, et al. “A New Approach of Uncovering Hidden Risks with Internal Threat Testing.” A New Approach of Uncovering Hidden Risks with Internal Threat Testing, 14 Dec. 2024, pp. 1–7, ieeexplore.ieee.org/abstract/document/10951104, https://doi.org/10.1109/sti64222.2024.10951104. Accessed 17 Apr. 2025. Orleans-Bosomtwe, Papa Kobina. “Critical Infrastructure Security: Penetration Testing and Exploit Development Perspectives.” ArXiv.org, 2024, arxiv.org/abs/2407.17256?utm. Accessed 16 Apr. 2025.