I did a pen testing course a while back and we were constantly told to make sure we had an air tight contract signed by as senior a person as possible before we started doing any work at all even just recon to make sure we were covered by the law. If they had their way, all CEOs would agree to pen tests in blood just to make it completely iron tight

I've also got multiple stories of people in IT or security who decided to investigate someone doing something dodgy internally without permission and getting fired themselves even though they caught the person in the act because they weren't permitted to do what they'd done!

