Ethical hacker vs cybercriminal: the difference, and how to become a white hat

Ethical hacker vs cybercriminal: the difference, and how to become a white hat

The Matrix is the most popular film about hackers ever made. It is films that shape our picture of a person with extraordinary powers, unlocking every secret of society with nothing but a computer. But is that how it is? In fact it is not so far from the truth: the world of cybersecurity is divided into two opposing sides — those who break into systems in order to protect them, and those who do it for personal gain. In this article we go through the kinds of hacker there are, what each is after, and how to build a career in ethical hacking.

The difference between an ethical hacker and a cybercriminal

To understand the categories and the differences between them, we need to discuss hacking itself. Hacking is generally understood as the process of examining, modifying and exploiting computer systems, software and networks in order to gain unauthorised — that is, unlawful — access. A hacker typically looks for vulnerabilities in a system (bug hunting) and for ways round its defences (bypassing security controls). They then exploit the bugs they found and mount an attack by various means.

It is precisely the legal aspects of that activity that let hackers be categorised by how they operate.

Ethical hackers (white hat)

They work strictly within the law and on behalf of companies, working ahead of the threat. They help find the weak points, the vulnerabilities, in security systems. The testing methods they use are no different from a criminal's, with the one difference that the system's owners have formally agreed to it. Their main aim can be described as improving data protection and preventing breaches by other groups.

Cybercriminals (black hat)

The opposite of white hats, with goals at the other pole of good and evil. These hackers get into systems without the owner's authorisation and use the vulnerabilities they find to steal data, extort money or spread malicious software. Most often the aim is unlawful financial gain, stealing data for later fraud, or damaging a company's reputation. Their targets are not always companies, either; sometimes they are private individuals. Needless to say, such activity is unlawful and can lead to serious consequences, imprisonment included.

Grey hats

There is also an intermediate category, the grey hats. They are often underestimated on the grounds that they break into systems without intending harm. But that does not change the fact that they too break in without the owner's permission, and however good the intentions behind it — usually a deliberate, public demonstration of vulnerabilities to draw attention to security problems, or a "notification" to a particular company — their actions are generally considered unauthorised and therefore unlawful.

The legal side of ethical hacking: laws and certifications

So can you stay on the ethical side, and why become an ethical hacker at all? Why are companies willing to spend budget on such specialists?

Ethical hacking is not merely a lawful alternative to cybercrime but a well-paid, promising profession. Despite the temptation of easy money in the black hat world, white hats remain in demand, because cyber threats keep growing more complex and businesses badly need to protect their data and infrastructure. The main reason to choose the ethical road is the chance to work within the law, avoiding prosecution and the risk of losing your freedom. And modern technology lets you earn a decent reward without crossing to the dark side. Companies are willing to pay for security, because a cyberattack can cost them millions and destroy their reputation.

Organisations invest in ethical hackers because their work helps prevent data breaches that could lead to fines and litigation, finds vulnerabilities before attackers exploit them, and strengthens customers' trust by demonstrating a high level of cyber defence.

For a hacker's activity to count as ethical, it has to meet these criteria:

  • Formal permission from the system's owners before any action is taken, set down on paper with a full list of conditions. Do not forget that it is better to be cautious: protecting yourself legally is your own responsibility, so you need to know the law thoroughly before you test anything.
  • Confidence that you are complying with every law and cybersecurity standard — ISO/IEC 27001, the international standard for information security management, or the NIST Cybersecurity Framework, the set of recommendations from the US National Institute of Standards and Technology, among others.
  • Complete confidentiality of the data, with a signed undertaking not to use it for any purpose not documented in advance.
    An undertaking to disclose every vulnerability found to the company, with nothing held back.

As for the law governing this field, different countries have different rules and there are no unified standards. For each country you will need to study the legislation and the security standards. But what you can do right now is get certified:

  • Certified Ethical Hacker (CEH) — one of the best known and most popular certifications for ethical hackers.
  • Offensive Security Certified Professional (OSCP) — a more practical examination requiring the ability to break into real systems (be careful here too, and commit no unlawful acts).
  • GIAC Penetration Tester (GPEN) — a certification confirming penetration testing skills.

How to become an ethical hacker, and where the career leads

It is no secret that there is no school of ethical hacking as such, since it is a combination of knowledge from several fields and the practical application of highly specialised experience. But that need not stop you. What it takes is knowledge of information security, the same as cybersecurity specialists study, plus some enthusiasm and a leaning towards learning new things. For convenience we have set out a plan that will open the way:

  1. Get the tech fundamentals. Before going deeper into hacking you need the foundations of networking, operating systems, programming and cybersecurity — on the Cybersecurity Analyst course, for instance, which includes an internship. It is worth studying networking fundamentals (TCP/IP, DNS, VPN, NAT, firewalls), operating systems (Linux, Windows, macOS), programming languages (Python, Bash, C, PowerShell) and web application security fundamentals (the OWASP Top 10).
  2. Practise and take part in CTF competitions. Capture the Flag events are cybersecurity competitions where participants solve break-in problems in a controlled environment. An excellent way to sharpen your skills and learn new techniques.
  3. Learn the tools. An ethical hacker needs command of the tools used in penetration testing: Kali Linux, a distribution including most hacking tools; Burp Suite, for analysing and exploiting web application vulnerabilities; the Metasploit Framework, for automating penetration testing; Wireshark, for analysing network traffic; and Nmap, for scanning networks.
  4. Get certified and look for work. Certification improves your chances of being hired. With a CEH or OSCP you can look for vacancies at cybersecurity companies or try bug bounty programmes — schemes under which companies, organisations or government bodies offer a reward for finding vulnerabilities in their products, services or infrastructure.

What you learn can be applied at large tech companies, banks, government bodies and cybersecurity firms. The roles open to you include:

  • Cybersecurity analyst — analyses threats, finds vulnerabilities in systems, develops security policy and responds to incidents.
  • Penetration tester — checks systems for vulnerabilities.
  • SOC analyst — monitors attacks in real time.
  • Vulnerability researcher — hunts for zero-day bugs and develops defences against them.
  • Cybersecurity consultant — helps companies build a defence strategy.

Average salaries in the field range from $70,000 to $150,000 a year, depending on experience and region.

In closing: ethical hacking is a lawful, well-paid road for anyone who wants to protect the digital world using a hacker's knowledge. If you have a passion for technology and a wish to understand systems at a deep level, now is the time to start in cybersecurity. Just remember always to stay on the right side of it.

Read next