Skip to content
Cipher Bridge
The one rule. Testing is legal only with the owner's authorisation, because US and UK computer misuse laws turn on it. So Cipher Bridge tests only systems you own or are explicitly authorised to test.

Learn it

Penetration testing labs: building a safe one at home

Penetration testing labs let you practise on hardware you own, so nobody else's system is ever at risk. However, a lab is only safe if it is isolated. Also, it is only useful if you write up what you do in it.

  • Authorisation before any test
  • Plain-English guidance
  • Written scope on every engagement
Penetration testing labs: isolate it, fill it and write it up

Why penetration testing labs matter

Hosted platforms are excellent, but they decide what you practise. By contrast, your own lab lets you build the systems first and then test them. Therefore you learn how things break as well as how they work.

What goes into penetration testing labs

A small lab is enough to start. Also, most of it can run as virtual machines on one computer.

  • A virtualisation tool on hardware you own
  • One or two deliberately vulnerable machines
  • A normal server you configure yourself
  • A separate network that cannot reach your home devices
Lab pieceWhyTip
Isolated networkKeeps practice contained.No route to the internet when testing.
Vulnerable appA safe target.For example, OWASP Juice Shop.
Your own serverTeaches defence too.Harden it, then test it.

Check your penetration testing labs

Tick what is true about your lab today.

Your result appears here as you tick, so you can see what is still open.

Keeping penetration testing labs safe

Isolation is the whole safety model. So keep lab networks separate from family devices, and never expose a deliberately vulnerable machine to the internet. In addition, snapshot each machine, because you will break things.

Turning lab work into a record

Write up each exercise against a published method, for example the OWASP Web Security Testing Guide or the Penetration Testing Execution Standard. As a result, hiring managers can see how you think.

From lab to profession

A lab builds skill, while a profession needs authorisation. Therefore real-world testing always starts with the owner's written permission. Both the US Computer Fraud and Abuse Act guidance and the UK Computer Misuse Act 1990 turn on it.

Penetration testing labs questions

Do penetration testing labs need expensive hardware?

No. One computer running virtual machines is enough to start.

Are penetration testing labs legal?

Yes, on hardware you own and networks you control.

Should my lab reach the internet?

Not while vulnerable machines are running.

How do I show employers my lab work?

Publish clear write-ups that follow a published method.

Related guides

Need your own systems tested?

If your organisation needs authorised testing rather than a lab, tell us what you are protecting. A senior practitioner replies within one business day.

Ask about authorised testing