Learn it
Penetration testing and ethical hacking: one discipline, two words
People use penetration testing and ethical hacking as if they meant the same thing. They mostly do. However, the small difference matters when you are hiring, and it matters again when you are choosing what to learn.
- Authorisation before any test
- Plain-English guidance
- Written scope on every engagement
How penetration testing and ethical hacking overlap
Both mean attacking a system on purpose, with the owner's written permission. Therefore the techniques are the same, and so is the legal line. However, only the framing differs.
Where penetration testing and ethical hacking differ
Ethical hacking is the broad discipline. By contrast, a penetration test is one bounded engagement inside it, with a scope, a window and a report.
| Ethical hacking | Penetration testing | |
|---|---|---|
| What it is | The whole discipline. | One defined engagement. |
| Boundaries | Set by each piece of work. | A signed scope and window. |
| Output | Varies by role. | A report with evidence. |
Penetration testing and ethical hacking: which do you need?
Tick what applies to you. The result points to the right path.
Your result appears here as you tick, so you can see what is still open.
Which word to use when you hire
Ask for a penetration test when you need evidence for a customer, an auditor or an investor. So the request should name the systems, the deadline and who will read the report. In addition, check that the firm follows a published method such as the Penetration Testing Execution Standard.
Which word to use when you learn
Courses often say ethical hacking, while job adverts usually say penetration tester. Also, employers hire on demonstrated ability. Therefore lab write-ups and a coordinated disclosure record matter more than which label a course uses.
The legal line for both
In the United States, the US Computer Fraud and Abuse Act guidance turns on authorisation. Similarly, the UK Computer Misuse Act 1990 makes unauthorised access an offence. So whichever word you use, the owner's written permission is what keeps the work lawful.
Questions about penetration testing and ethical hacking
Are penetration testing and ethical hacking the same job?
Mostly. A penetration tester is one kind of ethical hacker, working on bounded engagements.
Is penetration testing and ethical hacking legal?
Yes, with the owner's written authorisation. Without it, both are offences.
Which pays better to learn?
Neither label decides pay. Demonstrated ability and a public record do.
What should a test report contain?
Scope, method, validated findings with evidence and a prioritised plan.
Related guides
Need a test rather than a lesson?
Tell us what you are protecting and what you are trying to prevent. A senior practitioner replies within one business day with a written scope and one fixed fee.
Ask about authorised testing