Hacking encompasses very different realities depending on who practices it, in what context, and with what authorization. Between a penetration test commissioned by a company and the malicious exploitation of a vulnerability, the techniques may be similar, but the legal framework and intent diverge radically. Measuring these gaps helps to understand why cybersecurity increasingly relies on authorized hackers to protect its systems.
Security by Design: What the Cyber Resilience Act Changes for Ethical Hacking
Competitors approach ethical hacking as a one-off testing practice. The European regulatory framework has shifted the focus. The Cyber Resilience Act (CRA) of the European Union imposes a “default” and “by design” security logic on manufacturers of connected products, requiring them to address vulnerabilities throughout the product lifecycle.
This requirement transforms the role of the ethical hacker. It is no longer just about simulating an attack on a defined perimeter and then delivering a report. Security researchers now intervene upstream, from the development phase, to ensure that software components (including open source dependencies) comply with the CRA’s obligations.
The European ecosystem for coordinated vulnerability disclosure has been structured in parallel. The resources available on hucky.org document this evolution where national CSIRTs and ENISA serve as coordination relays, with a European vulnerability database operational since 2025. Reporting a vulnerability in Europe now follows a formalized circuit, which legally secures the work of ethical hackers.

Ethical Hacking vs. Malicious Hacking: A Comparison of Practices
The tools are often the same. What distinguishes an authorized penetration test from a criminal attack hinges on four criteria documented in most cybersecurity frameworks.
| Criterion | Ethical Hacking (white hat) | Malicious Hacking (black hat) |
|---|---|---|
| Authorization | Written contract with the system owner | No authorization |
| Scope | Defined scope, objectives, and time window | No limits, opportunistic exploitation |
| Impact on services | Designed to minimize disruptions | Disruption sought or ignored |
| Outcome | Remediation report with recommendations | Data theft, ransomware deployment, resale |
The written authorization of the system owner is the only element that legally separates the two practices. A pentester who exceeds the defined perimeter in their contract crosses into illegality, even if their intent remains defensive.
So-called “grey hat” hackers fall between the two. They identify vulnerabilities without prior authorization and then notify the concerned company. This practice remains legally risky in most European jurisdictions, despite the structuring of coordinated disclosure mechanisms.
System Vulnerabilities and Human Factor: Where Attacks Concentrate
A common idea is that cyberattacks primarily exploit technical flaws in systems. Field data shows a more nuanced picture.
Cybersecurity issues often stem from a lack of user awareness, not just software vulnerabilities. Phishing, social engineering, and the reuse of compromised passwords remain attack vectors that do not require any sophisticated technical exploitation.
Ethical hacking covers both dimensions. A comprehensive penetration test generally includes:
- Attempts to exploit technical vulnerabilities on the company’s systems, networks, and web applications
- Simulated phishing campaigns to assess employee responsiveness to fraudulent emails
- Physical access tests (attempts to intrude into premises, plugging in compromised USB drives) to measure non-digital controls
In contrast, the majority of companies commissioning a security audit limit themselves to the technical aspect. Software supply chain auditing remains under-practiced despite the regulatory scope widening to include third-party components and open source dependencies imposed by the CRA.
Cybersecurity Professions: Technical Skills and Salary Levels
The cybersecurity sector suffers from a marked imbalance between supply and demand. In France, over 100,000 cybersecurity positions remain unfilled. This deficit fuels upward salary pressure across the entire industry.
The sought-after profiles cover a wide spectrum:
- Pentester (penetration tester): mastery of exploitation techniques, network auditing tools, and scripting languages. Starting salary around 42,000 euros gross annually
- SOC Analyst (Security Operations Center): real-time monitoring of security events, alert analysis, and incident response
- CISO (Chief Information Security Officer): steering a company’s security strategy, a senior profile whose salary can reach 130,000 euros gross annually
The common technical foundation for these professions relies on understanding operating systems (especially Linux), network protocols, and at least one programming language. Specialization occurs after this foundation, not before.

Product Compliance and Vulnerability Disclosure: The New Scope of the Ethical Hacker
Ethical hacking is no longer limited to traditional penetration testing. The obligation to document and manage the software supply chain, including integrated open source components, brings this discipline closer to software supply chain auditing.
A security researcher who discovers a vulnerability in a third-party component used by thousands of connected products triggers a coordination process involving the manufacturer, the competent national CSIRT, and potentially ENISA. This formalized circuit reduces the risk of wild disclosure but requires ethical hackers to be familiar with regulatory procedures in addition to exploitation techniques.
Ethical hacking has become a product compliance issue, not just a one-off testing practice. Companies that integrate security researchers from the design phase of their connected products simultaneously meet CRA requirements and reduce their attack surface. Those that continue to treat security as a final check expose themselves to regulatory non-compliance and exploitable vulnerabilities in production.



