And here we end up back with irjustin's proposal that if pentesters are doing things that would be illegal without proper permission, they need to be prepared to spend some time in jail. Their risks there for which they need to be compensated include their own organisation failing in their due diligence and sending them into a test for which they're genuinely not legally authorised.