These get used interchangeably, and it costs people money — they train for one job while applying for another.
Updated 2 October 2026
Cybersecurity is the whole field of protecting systems, data and people from attack. Ethical hacking is one specialism inside it: attacking systems, with permission, to find weaknesses before real attackers do.
Every ethical hacker works in cybersecurity. Most cybersecurity professionals are not ethical hackers.
Ethical hackers are also called penetration testers or red teamers. The work is usually project-based: agree the scope and rules in writing with the client, probe the systems in scope, find and prove weaknesses, then write a report explaining each finding and how to fix it. A large share of the job is writing and explaining, not only technical work.
It is legal when it is done with the system owner's explicit written permission and within an agreed scope. Testing systems you do not own or have permission to test can break the law. Practise only in your own lab or on purpose-built practice targets, get permission in writing for any real engagement, and ask a lawyer if you are unsure.
Yes. The foundations overlap heavily, and experience on one side makes you better at the other: attackers who have worked in defence write more useful reports, and analysts who understand attack techniques spot them faster.
You can start without it. Networking, Linux and web fundamentals come first. Scripting becomes more valuable as you advance, but it is not a prerequisite for beginning.
The techniques an ethical hacker uses are the same ones a criminal uses. What separates them is written authorisation from the system's owner and a scope both sides have agreed. Without that, it is not ethical hacking.
Analysts work on the defending side: monitoring alerts from security tools, investigating whether something is a real incident or a false alarm, escalating and responding, and improving detection so the same issue is caught faster next time.
The work is ongoing rather than project-based, often runs in shifts, and involves a lot of reading logs and following procedures. It rewards patience and pattern recognition.
If you are unsure, learn the foundations both share: networking, Linux and basic security concepts. They carry over to either path, so nothing is wasted.
After that, a rough guide. If you enjoy taking things apart, thinking like an attacker and writing detailed reports, lean offensive. If you prefer steady investigation, spotting patterns and working to a process, lean defensive. Defensive roles are generally more numerous than specialist offensive ones, which is one reason many people start there.
If you want to try the offensive side before committing, our Ethical Hacking Starter lets you do footprinting, scanning, enumeration and basic vulnerability assessment hands-on. The full Ethical Hacking course goes further into Linux, web application security and API security.