Skip to content
Cipher Bridge
The one rule. Testing is legal only with the owner's authorisation, because US and UK computer misuse laws turn on it. So Cipher Bridge tests only systems you own or are explicitly authorised to test.

Learn it

Penetration testing and ethical hacking: one discipline, two words

People use penetration testing and ethical hacking as if they meant the same thing. They mostly do. However, the small difference matters when you are hiring, and it matters again when you are choosing what to learn.

  • Authorisation before any test
  • Plain-English guidance
  • Written scope on every engagement
Penetration testing and ethical hacking: define it, compare it and choose it

How penetration testing and ethical hacking overlap

Both mean attacking a system on purpose, with the owner's written permission. Therefore the techniques are the same, and so is the legal line. However, only the framing differs.

Where penetration testing and ethical hacking differ

Ethical hacking is the broad discipline. By contrast, a penetration test is one bounded engagement inside it, with a scope, a window and a report.

Ethical hackingPenetration testing
What it isThe whole discipline.One defined engagement.
BoundariesSet by each piece of work.A signed scope and window.
OutputVaries by role.A report with evidence.

Penetration testing and ethical hacking: which do you need?

Tick what applies to you. The result points to the right path.

Your result appears here as you tick, so you can see what is still open.

Which word to use when you hire

Ask for a penetration test when you need evidence for a customer, an auditor or an investor. So the request should name the systems, the deadline and who will read the report. In addition, check that the firm follows a published method such as the Penetration Testing Execution Standard.

Which word to use when you learn

Courses often say ethical hacking, while job adverts usually say penetration tester. Also, employers hire on demonstrated ability. Therefore lab write-ups and a coordinated disclosure record matter more than which label a course uses.

The legal line for both

In the United States, the US Computer Fraud and Abuse Act guidance turns on authorisation. Similarly, the UK Computer Misuse Act 1990 makes unauthorised access an offence. So whichever word you use, the owner's written permission is what keeps the work lawful.

Questions about penetration testing and ethical hacking

Are penetration testing and ethical hacking the same job?

Mostly. A penetration tester is one kind of ethical hacker, working on bounded engagements.

Is penetration testing and ethical hacking legal?

Yes, with the owner's written authorisation. Without it, both are offences.

Which pays better to learn?

Neither label decides pay. Demonstrated ability and a public record do.

What should a test report contain?

Scope, method, validated findings with evidence and a prioritised plan.

Related guides

Need a test rather than a lesson?

Tell us what you are protecting and what you are trying to prevent. A senior practitioner replies within one business day with a written scope and one fixed fee.

Ask about authorised testing