Two paths, one subject

Ethical hacking: learn it, or hire it

Most people arriving here want one of two things from ethical hacking. Either you want to do ethical hacking yourself, or you need someone to do it to your systems. Therefore this page splits cleanly in two, and neither path is padded with hype.

Path one

Learn it

The honest route into ethical hacking, including what the certifications are worth and where you are legally allowed to practise.

  • What ethical hacking involves day to day
  • The certification ladder, in order
  • Where practising is lawful, and where it is not
Start with the basics
Path two

Hire it

We are a working practice as well as a guide. If your organisation needs authorised testing, we take a limited number of engagements.

  • Named senior practitioners, no junior bench
  • Fixed fee, agreed before anyone starts
  • Signed authorisation before any testing
See how engagements work
Definitions

What ethical hacking actually is

Ethical hacking is attacking a system on purpose, with the owner's written permission, in order to find what a real intruder would find first. The techniques are identical to criminal intrusion. Only the permission differs, and that difference is everything.

Ethical hacking is not a scan

Automated tools list issues one at a time. A practitioner links them into a path and proves the impact, because that is what an attacker would do.

Ethical hacking is not a hobby

Real engagements run on signed scopes, agreed testing windows and evidence handling. That paperwork is not bureaucracy, since it is what keeps the work lawful.

Ethical hacking is not security research

Finding a bug in software you own is research. Probing somebody else's live system without consent is an offence, although the skills overlap completely.

Ethical hacking is not one job title

It covers application testing, network and cloud work, red teaming and detection engineering. Consequently the route in varies more than most guides admit.

Path one

How to get into ethical hacking

Ethical hacking has no shortcut, but there is an order that works. Each rung below assumes the one before it, and every practice environment named here is one you are explicitly allowed to attack.

01
Learn the systems firstEthical hacking rests on networking, operating systems, and at least one scripting language. You cannot break what you do not understand, so this stage is longer than most people want it to be.
02
Practise only where you are invitedBuild a lab on hardware you own, or use platforms that exist for the purpose. TryHackMe and Hack The Box both give you targets you are permitted to attack. Never practise on a system that is not yours.
03
Work through a real methodologyRead the OWASP Web Security Testing Guide and the Penetration Testing Execution Standard. They turn scattered tricks into a repeatable process, which is what employers are buying.
04
Take a practical certificationThe OSCP is a 24-hour hands-on exam and remains the usual entry credential. Multiple-choice certifications teach vocabulary, although they prove far less about capability.
05
Build a public recordWrite up your ethical hacking lab work, report bugs through a coordinated disclosure programme, and publish what you learn. Because hiring managers cannot see your exam, they read your writing instead.
06
Enter through an adjacent roleMany practitioners arrive from system administration, development, or a security operations desk. That route is slower on paper, but it produces better testers, since they already know how real estates break.
An honest note about the courses being sold to you

Ethical hacking has a large training industry attached to it, and much of it oversells. A certificate does not produce a job offer on its own. Employers hire on demonstrated ability, so the lab write-ups and the disclosure record matter more than the badge count.

Path two

When to hire an ethical hacking team

If you landed here for your business rather than your career, this is the shorter path. These are the three moments organisations usually buy ethical hacking.

Before somebody asks

An enterprise customer, an insurer or an investor wants evidence of testing. A real report answers that, while a scan export usually does not.

After a change

A migration, a merger, or a new public-facing product. Each one creates paths that did not exist last quarter, therefore the old report no longer describes your estate.

After a scare

Something happened, and you need to know what else is reachable. We map it under authorisation, and we do not chase whoever did it.

$35,000 to $120,000

Where a full ethical hacking engagement usually lands, agreed as one fixed fee after a written scoping brief. The floor for a full engagement is $25,000. However, that is not the only door, because the bounded review below is a different engagement rather than a shrunken one.

A bounded ethical hacking review

from $4,500 Second door

The External Attack Surface Review is a bounded review of what you expose to the internet. We map your public estate, test it, and verify every finding by hand rather than sending you a scanner export. Scope is fixed at up to five external hosts and one public web application. Your report then arrives within five business days.

Suited to

  • An enterprise customer, an insurer or an investor has asked for evidence of testing, and you have a date to meet.
  • Nothing external has ever been tested, so you first need to know what is actually reachable.
  • You would rather see how we work on something small before committing to a full programme.

Not this engagement

  • Internal network, Active Directory or cloud role review.
  • Business logic testing, or work that reads your source code.
  • Full exploitation chains against a defended estate.
  • Auditor-grade evidence for SOC 2 or PCI, which needs the full engagement above.

The fee is credited in full. Commission a full engagement within ninety days of your report and the whole review fee comes off the price. Consequently the review costs you nothing if you go on to the deeper work.

This is a different engagement, not a smaller version of the one above. Moreover, it is priced by scope rather than by depth of care. Consequently, where the review finds something that needs the deeper work, we say so plainly and quote it separately.

Full engagements run from $35,000 to $120,000, while the bounded External Attack Surface Review starts at $4,500. Indicate your approximate figure so we can scope the right level of testing.

A senior practitioner replies within one business day.

Common questions

Questions about ethical hacking

Is ethical hacking legal?

Yes, when the owner of the system has authorised it in writing. Without that permission the same actions are a criminal offence. In the United Kingdom that holds regardless of your intentions, so authorisation is not a formality.

Do I need a degree to work in ethical hacking?

No. Most practitioners arrive through system administration, development or security operations, and demonstrated ability matters far more than a qualification. A practical certification plus a public record of your work is the usual combination.

Which ethical hacking certification should I take first?

A hands-on one. The OSCP is a 24-hour practical exam and remains the common entry credential for testing roles. Multiple-choice certifications can help with vocabulary, although employers weigh them much less.

Where can I practise legally?

On hardware you own, in a lab you built, or on platforms that exist to be attacked such as TryHackMe and Hack The Box. Never point tools at a system you were not invited to test, because that alone can be an offence.

How long does it take to become employable?

For most people ethical hacking takes one to three years of consistent study alongside other work. That range is wide because it depends heavily on your starting point, so someone already administering systems moves much faster.

What does an ethical hacking engagement cost?

There are two. A full ethical hacking engagement is fixed-fee from $25,000, and most land between $35,000 and $120,000. Alternatively, the bounded External Attack Surface Review starts at $4,500 and covers up to five external hosts and one web application. Both are quoted as one number after a written scoping brief, therefore neither is billed hourly. Moreover, the review fee is credited in full against a full engagement commissioned within ninety days.

Do you offer training or courses?

No. This page is the ethical hacking guidance we give, and it is free. Our paid work is authorised testing for organisations, therefore we have no course to sell you at the end of the article.

Email us