Cyber Security: What is a Penetration Tester?

By EJN Labs · 31 Jul 2025 · 3 min

A penetration tester (often shortened to pen tester or ethical hacker) is a security professional engaged to simulate the behaviour of a real attacker against an authorised target. The goal is to discover and demonstrate exploitable weaknesses, rate their business impact, and provide concrete remediation guidance before a malicious actor finds the same flaws.

What a penetration tester does

A penetration tester scopes the engagement, performs reconnaissance, identifies vulnerabilities, exploits them in a controlled way to demonstrate impact, explores how far an attacker could pivot once inside, and then delivers a written report and debrief. Each stage feeds the next, taking the assessment from agreed targets through to verified findings.

Scoping is where tester and client agree on targets, attack scenarios, schedules, and rules of engagement. Reconnaissance gathers open-source intelligence and maps the attack surface, vulnerability identification combines automated scanning with manual review, and exploitation confirms which findings are real. Once fixes have been applied, the engagement often closes with a re-test.

Core skills

Strong testers combine breadth and depth: working knowledge of networking, operating systems, web application architecture, cloud platforms, and at least one scripting language; comfort with command-line tools and the Linux file system; the ability to read and reason about source code; and clear written and spoken English so that findings translate into action for client stakeholders.

Common qualifications

Industry-recognised certifications include OSCP (Offensive Security Certified Professional), CREST CRT and CCT for UK-recognised technical credentials, and PNPT or HTB CPTS for hands-on practical assessments. CREST membership is often required for testing in regulated UK industries such as financial services and government supply chains, and for testers participating in the NCSC CHECK scheme.

Ethics and authorisation

The defining characteristic of a penetration tester is written authorisation. Testing without explicit permission is unlawful in the UK under the Computer Misuse Act 1990, regardless of intent. Professional engagements include a signed statement of work, defined scope, agreed escalation paths, and confidentiality terms before any technical activity begins.

Related terms

See also: penetration testing, ethical hacker, OSCP certification, and grey-box penetration testing.

Leave a Reply

Your email address will not be published. Required fields are marked *