Two paths, one subject

Ethical hacking: learn it, or hire it

Most people arriving here want one of two things. Either you want to do ethical hacking yourself, or you need someone to do it to your systems. Therefore this page splits cleanly in two, and neither path is padded with hype.

Path one

Learn it

The honest route into the field, including what the certifications are worth and where you are legally allowed to practise.

  • What the work actually involves day to day
  • The certification ladder, in order
  • Where practising is lawful, and where it is not
Start with the basics
Path two

Hire it

We are a working practice as well as a guide. If your organisation needs authorised testing, we take a limited number of engagements.

  • Named senior practitioners, no junior bench
  • Fixed fee, agreed before anyone starts
  • Signed authorisation before any testing
See how engagements work
Definitions

What ethical hacking actually is

Ethical hacking is attacking a system on purpose, with the owner's written permission, in order to find what a real intruder would find first. The techniques are identical to criminal intrusion. Only the permission differs, and that difference is everything.

It is not a scan

Automated tools list issues one at a time. A practitioner links them into a path and proves the impact, because that is what an attacker would do.

It is not a hobby

Real engagements run on signed scopes, agreed testing windows and evidence handling. That paperwork is not bureaucracy, since it is what keeps the work lawful.

It is not the same as security research

Finding a bug in software you own is research. Probing somebody else's live system without consent is an offence, although the skills overlap completely.

It is not one job title

The field covers application testing, network and cloud work, red teaming and detection engineering. Consequently the route in varies more than most guides admit.

Path one

How to get into ethical hacking

There is no shortcut, but there is an order that works. Each rung below assumes the one before it, and every practice environment named here is one you are explicitly allowed to attack.

01
Learn the systems firstNetworking, operating systems, and at least one scripting language. You cannot break what you do not understand, so this stage is longer than most people want it to be.
02
Practise only where you are invitedBuild a lab on hardware you own, or use platforms that exist for the purpose. TryHackMe and Hack The Box both give you targets you are permitted to attack. Never practise on a system that is not yours.
03
Work through a real methodologyRead the OWASP Web Security Testing Guide and the Penetration Testing Execution Standard. They turn scattered tricks into a repeatable process, which is what employers are buying.
04
Take a practical certificationThe OSCP is a 24-hour hands-on exam and remains the usual entry credential. Multiple-choice certifications teach vocabulary, although they prove far less about capability.
05
Build a public recordWrite up your lab work, report bugs through a coordinated disclosure programme, and publish what you learn. Because hiring managers cannot see your exam, they read your writing instead.
06
Enter through an adjacent roleMany practitioners arrive from system administration, development, or a security operations desk. That route is slower on paper, but it produces better testers, since they already know how real estates break.
An honest note about the courses being sold to you

Ethical hacking has a large training industry attached to it, and much of it oversells. A certificate does not produce a job offer on its own. Employers hire on demonstrated ability, so the lab write-ups and the disclosure record matter more than the badge count.

Path two

When to hire an ethical hacking team

If you landed here for your business rather than your career, this is the shorter path. These are the three moments organisations usually call us.

Before somebody asks

An enterprise customer, an insurer or an investor wants evidence of testing. A real report answers that, while a scan export usually does not.

After a change

A migration, a merger, or a new public-facing product. Each one creates paths that did not exist last quarter, therefore the old report no longer describes your estate.

After a scare

Something happened, and you need to know what else is reachable. We map it under authorisation, and we do not chase whoever did it.

from $25,000

Fixed fee, agreed after a scoping call, most engagements between $35,000 and $120,000. If your budget is materially lower we will say so rather than shrink the work to fit.

The minimum engagement is $25,000. A range is fine, since it tells us what depth to scope.

A senior practitioner replies within one business day.

Common questions

Questions about ethical hacking

Is ethical hacking legal?

Yes, when the owner of the system has authorised it in writing. Without that permission the same actions are a criminal offence. In the United Kingdom that holds regardless of your intentions, so authorisation is not a formality.

Do I need a degree to work in ethical hacking?

No. Most practitioners arrive through system administration, development or security operations, and demonstrated ability matters far more than a qualification. A practical certification plus a public record of your work is the usual combination.

Which ethical hacking certification should I take first?

A hands-on one. The OSCP is a 24-hour practical exam and remains the common entry credential for testing roles. Multiple-choice certifications can help with vocabulary, although employers weigh them much less.

Where can I practise legally?

On hardware you own, in a lab you built, or on platforms that exist to be attacked such as TryHackMe and Hack The Box. Never point tools at a system you were not invited to test, because that alone can be an offence.

How long does it take to become employable?

For most people it is one to three years of consistent study alongside other work. That range is wide because it depends heavily on your starting point, so someone already administering systems moves much faster.

Do you offer training or courses?

No. This page is the guidance we give, and it is free. Our paid work is authorised testing for organisations, therefore we have no course to sell you at the end of the article.