Ethical Hacking or Penetration Testing? What to Actually Ask Before You Buy

by Rebecca Sutton

If two security suppliers send you quotes, one for “ethical hacking” and one for “penetration testing”, don’t assume you’re comparing like for like. Penetration testing vs ethical hacking isn’t just a matter of branding. Ethical hacking is the broad, authorised practice of probing systems the way an attacker would. A penetration test is one specific, tightly scoped form of it. It comes with fixed dates, agreed rules and a written report. Knowing that difference before you sign anything stops you buying less than you think you’re getting.

Two colleagues reviewing a security testing proposal with charts before signing

This isn’t a semantic complaint. It affects what you can hold a supplier to. It affects what evidence you’ll have for an auditor or an insurer. And it affects what happens if something goes wrong during testing.

Penetration testing vs ethical hacking: start with what “ethical hacking” promises

Ethical hacking is a description of intent and authorisation, not a fixed deliverable. It covers anyone using attacker techniques with permission, for a defensive purpose. The US National Institute of Standards and Technology describes this role as a “white hat”: someone who breaks into systems specifically to evaluate and improve an organisation’s security.

A supplier advertising “ethical hacking services” could mean any of the following:

  • A scoped penetration test against one application or network
  • An ongoing bug bounty programme
  • A red team exercise against your whole organisation
  • Ad hoc vulnerability research with no fixed report format

None of that is dishonest marketing. It’s a broad category being used as a label. Broad labels don’t tell you what’s actually in scope.

Then check what a penetration test specifically includes

Penetration testing has a narrower, more mechanical definition. NIST’s technical guide to information security testing describes it as testing in which evaluators copy real-world attacks. The goal is to find gaps in an app, system or network’s defences. That’s a structured, repeatable process, not just a general skillset.

A genuine penetration test, whatever it’s called on the invoice, should always include:

  1. A written scope of work naming the exact systems, IP ranges or applications under test
  2. Rules of engagement covering testing windows, escalation contacts and any excluded techniques
  3. A fixed start and end date, not an open-ended arrangement
  4. A formal report with severity ratings, evidence and remediation steps

The National Cyber Security Centre describes penetration testing as a method for gaining assurance in an organisation’s security. Testers use the same tools and techniques an adversary might use. The NCSC also warns that a test only confirms a system isn’t vulnerable to known issues on the day it ran. Buy it as a point-in-time assurance exercise, not an ongoing guarantee.

Six questions to ask before you commit

Whatever term is on the proposal, put these questions to any supplier before you sign:

  • What exactly is in scope, and what is explicitly excluded?
  • Will I receive a written scope of work and rules of engagement before testing starts?
  • Is this a fixed-term test, or an ongoing service, and which does my compliance requirement actually need?
  • What does the final report contain, and does it include severity ratings and remediation guidance?
  • Is a retest included once fixes are made, or is that a separate cost?
  • What happens if the tester finds something outside the agreed scope?

A supplier who answers all six clearly, and in writing, is worth taking seriously. That’s true whether they describe the work as ethical hacking or penetration testing. Vague answers to two or three of these are a warning sign, whatever the service is called.

Why the terminology gets blurred on purpose sometimes

“Ethical hacking service” sounds broader and more impressive than “one scoped web application test”. Some suppliers lean on that, and it isn’t always misleading. Plenty of firms use the terms loosely because their staff and clients do too.

But check the small print if compliance is riding on it. If your business needs evidence of a scoped penetration test for Cyber Essentials Plus, PCI DSS or a client’s security questionnaire, a general “ethical hacking review” might not satisfy it. That’s especially true if it has no fixed scope and no formal report.

Check what the requirement actually specifies before you buy. Some frameworks name “penetration testing” explicitly. Others accept broader ethical hacking activity, including bug bounty evidence, as part of a wider assurance programme. Getting this wrong means paying twice: once for the wrong service, then again for the one you actually needed.

Where bug bounty and red teaming fit into a buying decision

Two ethical hacking activities regularly get compared to penetration testing, so it’s worth knowing where they sit.

A bug bounty programme pays independent researchers for confirmed vulnerabilities on an ongoing basis. There’s no single accountable tester and no fixed end date. Coverage depends on what researchers choose to look at. It complements a penetration test well, but it isn’t usually a replacement, particularly where one specific system needs guaranteed coverage within a set window. We’ve set out the trade-offs in full in bug bounty vs penetration testing.

A red team engagement is scoped differently again. Testers work towards one objective, such as reaching a finance system, rather than cataloguing every flaw. Your team tries to detect them along the way. It’s excellent for testing detection and response, but it won’t give you the exhaustive technical coverage a penetration test provides.

If your procurement need is “prove this application has been thoroughly tested”, a penetration test is what satisfies that. A bounty programme or a red team exercise won’t, on their own.

The legal foundation is the same for both

Every version of this work rests on the same legal basis in the UK, however it’s labelled. Section 1 of the Computer Misuse Act 1990 makes it a crime to access a computer program or data without permission. The offence applies if the person meant to get that access, and knew it wasn’t allowed. Written permission from the real system owner is what turns testing from a crime into a legitimate job. That’s true whether it’s called ethical hacking or penetration testing. Our guide to penetration testing and UK law covers exactly how that permission works in practice. Any supplier who can’t produce clear written terms on this as standard shouldn’t go near your systems.

Getting a scoped test that actually matches what you need

Once you know the scope, timeframe and report format you need, commissioning the right engagement gets much easier. Aardwolf Security runs scoped penetration tests across web applications, networks, APIs and cloud environments for UK businesses, built around a written scope of work from day one. If you’d like a second opinion on a proposal before you sign it, or want to talk through what a properly scoped test should include, you can get in touch here.

Frequently asked questions

Should my contract say “penetration testing” or “ethical hacking”?

Use whichever term matches your compliance requirement, but don’t rely on the label alone. Insist the contract specifies the scope, rules of engagement, timeframe and report format, regardless of which term appears on the cover page.

Is a cheaper “ethical hacking” quote ever actually a full penetration test?

Sometimes, yes. Some suppliers just prefer the broader term. But a lower price with vague scope and no mention of a formal report is more often a sign of reduced coverage. Compare scope of work documents directly, not headline prices.

Do I need both a penetration test and a bug bounty programme?

Many mature security programmes run both. A penetration test gives guaranteed, scoped coverage at a point in time. A bug bounty adds ongoing eyes on your estate between tests. Neither fully replaces the other.

What certifications should I look for in an ethical hacking or penetration testing supplier?

Look for recognised, testing-specific accreditation and hands-on delivery experience, rather than a general ethical hacking certificate alone. A broad qualification shows knowledge of the field. It doesn’t confirm someone can scope and deliver a proper engagement.

What’s the biggest risk of getting the terminology confused when buying?

Discovering, after an incident or an audit, that the assurance work you paid for doesn’t meet the standard your compliance framework or insurer actually required. Checking scope and deliverables before you buy avoids that entirely.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like