Ethical hacking is the authorised, legal use of attackers’ techniques to find security weaknesses before criminals do. A person with written permission probes your systems, reports what they find, and helps you fix it. The skills match a criminal’s. The permission, the rules and the goal are what make it ethical.
This guide explains what ethical hackers actually do, how the work differs from a penetration test, what the law says, and how to hire one without wasting money.
Table of Contents
What does an ethical hacker actually do?
An ethical hacker tries to break into a system the way a real attacker would, then tells the owner how it was done. IBM describes it as the use of hacking techniques by friendly parties to uncover, understand and fix security vulnerabilities.
The day-to-day work is less cinematic than the name suggests. Most of it is careful, methodical testing:
- Mapping what an attacker can see from the internet, such as websites, login pages and forgotten servers.
- Testing for weak passwords, missing patches and misconfigured services.
- Trying to chain small flaws into a serious breach.
- Testing people as well as machines, for example with phishing emails.
- Writing a clear report so that your IT team can fix what was found.
The report matters as much as the hacking. A finding nobody understands never gets fixed, so good testers explain each issue in plain terms, show how they exploited it, and suggest a fix your team can realistically carry out. Then they rank the findings, so you know what to tackle first and what can wait until next quarter.

What is the difference between white hat, black hat and grey hat?
The colours describe permission and intent. White hat hackers work with the owner’s consent and share findings only with the client. Black hat hackers break in for profit or to cause harm. Grey hat hackers sit in between: they may mean well, but they test systems without asking first.
That last group is where people get into trouble. Good intentions do not make unauthorised access legal, as the next section shows. Even so, plenty of well-meaning people have learned that the hard way.
Is ethical hacking legal in the UK?
Yes, but only with authorisation. The Computer Misuse Act 1990 makes it an offence to cause a computer to perform a function intending to secure unauthorised access to any program or data, knowing the access is unauthorised. Conviction on indictment can mean up to two years in prison, a fine, or both.
The Act has no general defence for good intentions. So the paperwork is what protects everyone. A proper engagement includes a signed scope, agreed test dates and named contacts. We cover the detail in our guide on why authorisation is the only thing that makes testing legal.
The same rule applies when you test your own cloud services, because you do not own the hardware underneath. Your provider may have its own testing policy, so check it first.
How is ethical hacking different from penetration testing?
Penetration testing is one kind of ethical hacking. Ethical hacking is the broad term, while penetration testing is a defined, scoped engagement within it, with a start date, an end date and a written report.
The NCSC defines a pen test as a method for gaining assurance in the security of an IT system by attempting to breach some or all of that system’s security. Other forms of ethical hacking include red team exercises, social engineering tests and vulnerability research.
| Activity | What it involves | Typical goal |
|---|---|---|
| Penetration test | Scoped, time-boxed attack on named systems | Find and prove exploitable flaws |
| Vulnerability assessment | Scanning and review without exploitation | List known weaknesses |
| Red team exercise | Open-ended, stealthy attack over weeks | Test detection and response |
| Social engineering test | Phishing, phone calls or on-site visits | Test staff awareness |
If you are new to the topic, start with our plain-English explanation of how a pen test works.
What skills and qualifications do ethical hackers have?
Good testers know networks, operating systems, web applications and how people behave under pressure. They also write well, because reporting is half the job.
Certifications help, but they are not the whole picture. The NCSC notes that the quality of a penetration test is closely linked to the abilities of the testers involved. So ask who will do the work, not just which logo the firm displays.
For government and critical national infrastructure work, the NCSC runs the CHECK scheme. Its buyer guidance says CHECK team leaders must hold Principal-level professional certification. Private-sector firms do not have to use CHECK providers, though many choose to.
Why would a business hire an ethical hacker?
The main reason is to learn about a weakness from someone on your side. The alternative is learning about it from a criminal, or from a regulator after a breach.
There are practical reasons too:
- Customers and insurers now often ask for evidence of testing.
- Standards such as ISO 27001 and PCI DSS expect it.
- It shows whether your patching and monitoring work in practice.
- It gives your board a factual view of risk, not a guess.
Be realistic about its limits, though. The NCSC is clear that a pen test can only validate that systems are not vulnerable to known issues on the day of the test. It complements good patching and monitoring. It does not replace them.
How do you hire an ethical hacker safely?
You are handing someone the keys to look for weak locks, so choose with care. A sensible process looks like this:
- Define the goal. Are you protecting customer data, meeting a standard, or checking a new application?
- Agree the scope in writing. List the systems, the test window and anything off limits.
- Ask who does the work. Request tester CVs and relevant certifications, and check them.
- Check the reporting. Ask for a sample report. It should rank findings and explain fixes plainly.
- Plan the retest. A fix is only proven once someone tests it again.
Also, be wary of anyone who promises to find nothing, or who offers a “hack” without a signed scope. Both are warning signs.
If you want a scoped test, Aardwolf Security runs penetration testing for UK organisations, and you can get in touch to talk through what would suit you. The guide above should help you judge any quote you receive, ours included.
Frequently asked questions
Can ethical hacking be done remotely?
Yes. External tests of websites, email and cloud services are done over the internet. Internal tests of office networks may be done remotely through a secure connection, or on site.
Will ethical hacking disrupt my business?
It should not. Testers agree safe methods and test windows in advance, and they stop if something looks fragile. Tell your team the test is happening so nobody mistakes it for a real attack.
How much does ethical hacking cost?
It depends on scope. The number of systems, their complexity and the depth of testing drive the price far more than the label on the service.
Do I need a CHECK-approved provider?
Only for central government and critical national infrastructure work. Private-sector buyers are not required to use CHECK providers, according to the NCSC’s buyer information.
Is a red team the same thing?
No. A red team exercise is a longer, stealthier test of your detection and response, not just your defences.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.