You're right 5768. Actually hacking the system might go to far if he doesn't get prior permission. I suppose a "safer" approach is to do a vulnerability test. Locate the actual holes and present to management the "likely" loss of data or damage the network would incur should someone exploit the vulnerabilities.
The point is to obtain some very real evidence to present to the managers. It is one thing to present hypothetical dangers and another to present real holes.
