---
description: In this article, we explore what is ethical hacking and how it can help small businesses protect themselves from cyberattacks.
image: https://gdm-localsites-assets-gfprod.imgix.net/images/capterra/og_logo-e5a8c001ed0bd1bb922639230fcea71a.png?auto=format%2Cenhance%2Ccompress
title: What is ethical hacking and how it can help your business
---

# What is ethical hacking and how can it help your business

Canonical: https://www.capterra.co.uk/blog/1620/what-is-ethical-hacking-help-your-sme

Published on 04/06/2020 | Written by Sonia Navarrete.

![What is ethical hacking and how can it help your business](https://images.ctfassets.net/63bmaubptoky/NlQDIV23RIPO9_2q4Qgtr3aCf14p6CJabcYM849E7nY/b3c9a22e66abc0343fb197fe300a80c0/James-Bond.png)

> Last year, more than 1.4 million SMEs in the UK were affected by a cyberattack,  costing the UK economy £8.8 billion overall. And with  over half of the British workforce working from home due to the COVID-19 pandemic, making sure your business is in safe hands is more relevant than ever. 

-----

## Article Content

Last year, more than 1.4 million SMEs in the UK were affected by a cyberattack,  costing the UK economy £8.8 billion overall. And with  over half of the British workforce working from home due to the COVID-19 pandemic, making sure your business is in safe hands is more relevant than ever. Since the beginning of the lockdown in the UK, more than 30% of SMEs have been victims of phishing emails, and almost half of those emails (45%) are related to COVID-19. In this article, we will explore:What is ethical hacking? How it can help small businesses protect themselves from cyberattacks and hacking.What is ethical hacking?According to the Cambridge English Dictionary, a hacker is a person “who is  skilled in the use of  computer systems , often one who  illegally obtains access to  private computer systems.” Now, imagine a person whose business is also  hacking private systems and data but to keep them safe instead.This is the figure of the  ethical hacker or ‘ white hat ’  hacker , someone who is trusted by the company to attempt to enter the organisation’s networks and systems carrying  penetration testing and an  ethical hack – and most times is a Certified Ethical Hacker. Both have the same knowledge, but the difference is that the ethical hacker is on the side of the law (and the company). An  ethical hacker performs the  hacking of a company using the same techniques than a  hacker would to test the company’s  cybersecurity measures and help them improve them against real attacks.Hiring an ethical hacker has been something that traditionally was seen as something that only large corporations could (and needed) to do. The value of identifying threats in advanceOne of the ways in which companies are strengthening their cybersecurity is by hiring white hat hackers or ethical hackers. Ethical hackers have a similar skill set as ‘ black hat ’ (malicious) hackers, and are able to find  vulnerabilities in your system via  penetration testing and  hacking into your system, with the flip side that they can also advise you on how to best prepare to avoid these.As threats become more sophisticated, companies need to look at other ways to defend themselves from these threats. In 2019, 60% of the companies hacked were medium-sized businesses. The Cyber Security Breaches Survey report issued by the government, also states that despite this figure, the number of businesses identifying cyber security breaches has decreased since 2017.Harman Singh, Managing Consultant at Defendza, explains the reasons why some SMEs fail to act on cyber security:“Some SMEs have a lack of proactive approach towards cyber security to ensure it is an organisation-wide priority. They also don’t see compliance as a priority and they rely on the IT services provider to take care of security without involving a specialist skill set.Several small businesses have experienced cyber attacks, and the majority of them are unaware. Digital revolution in recent years has exposed our professional and personal life, and it is essential that businesses are ready against potential threats.”Keep your company safe from attackersHowever, if hiring an ethical hacker is not in the cards for you, the National Cyber Security Centre (NCSC) provides guidance to organisations to ensure these use best practices to keep the information secure. Below we have listed four tips to make sure your data is in safe hands.1. AwarenessYou can have the most sophisticated system in place, hire an ethical hacker, and security applications, but unless your staff knows good security practices, it’s not worth it. Therefore training your staff is key, as well as making sure that they understand the real implications of an attack. The UK Government offers free online training for small and medium-sized businesses that helps employees understand the importance of cybersecurity and also provides practical tips to help them identify threats. 2. Keep your devices safeSmartphones and tablets are critical, but vulnerable devices used by businesses. It’s vital to secure them because they could contain sensitive company data or provide a backdoor into the company’s network.  The NCSC provides some tips for small businesses such as keeping devices and the apps up to date to make sure the latest security update is installed in the device. 3. PasswordsThe NCSC also recommends training your staff into best practices with passwords such as choosing the right length and tips on storing it.  Having a strong password is a must. Password management software can help with securing and storing passwords, keeping them in a digital vault. 4. BackupAs well as all of the above tips, it is also important to back up your data regularly. Backup software creates copies of the data that can be restored in case of a breach or a data loss.The NCSC recommends keeping data separate from the computer and considering the cloud, as the data is physically separate from the computer and also offers backup services at a lower cost and without having to invest in hardware.Neil Hammond gives some tips to keep your company’s cyber security updated:“Make sure that your staff is trained. There is plenty of material available to help with staff education, especially if it is done as “this will help you stay cyber-secure at home”. Also, keeping software up to date is important because reputable suppliers regularly patch their software for vulnerabilities. Finally, it is critical to keep good backups. A 3-2-1 strategy means having at least 3 total copies of your data, 2 of which are local but on different devices (for example 1 on memory stick and 1 on hard drive), and at least 1 copy offsite (and not connected directly to your main files).”Looking for cyber security software? Check out our cyber security software or backup software catalogue.

## About the author

### Sonia Navarrete

Sonia is a Senior Content Analyst at Capterra, helping SMEs choose the best software. She published in Raconteur, Computer Weekly and IT Pro. Journalist and PR. 

## Related Categories

- [Compliance Software](https://www.capterra.co.uk/directory/30110/compliance/software)
- [Cybersecurity Software](https://www.capterra.co.uk/directory/31037/cybersecurity/software)
- [Endpoint Protection Software](https://www.capterra.co.uk/directory/30907/endpoint-protection/software)
- [Network Security Software](https://www.capterra.co.uk/directory/30003/network-security/software)
- [Vulnerability Management Software](https://www.capterra.co.uk/directory/31062/vulnerability-management/software)

## Related Articles

- [5 best IT help desk ticketing systems for UK businesses](https://www.capterra.co.uk/blog/4308/best-IT-help-desk-ticketing-system-UK)
- [5 top-rated contract management systems for small businesses in the UK](https://www.capterra.co.uk/blog/4378/best-contract-management-software-UK)
- [UK PropTech: 70% used an app to search for a home](https://www.capterra.co.uk/blog/2613/uk-real-estate-proptech)
- [Security, data privacy, and surveillance concerns are challenges to smart city development](https://www.capterra.co.uk/blog/4201/Smart-city-technologies)
- [How are UK SMEs faring against ransomware in comparison to European neighbours?](https://www.capterra.co.uk/blog/2697/uk-sme-preparation-for-ransomware-european-neighbour-comparison)

## Links

- [View on Capterra](https://www.capterra.co.uk/blog/1620/what-is-ethical-hacking-help-your-sme)
- [Blog](https://www.capterra.co.uk/blog)
- [Home](https://www.capterra.co.uk/)

-----

## Structured Data

<script type="application/ld+json">
  {"@context":"https://schema.org","@graph":[{"name":"Capterra UK","address":{"@type":"PostalAddress","addressLocality":"Egham","addressRegion":"ENG","postalCode":"TW20 9AH","streetAddress":"Tamesis, The Glanty, Staines-upon-Thames Egham TW20 9AH United Kingdom"},"description":"Capterra UK helps millions of people find the best business software. With software reviews, ratings, infographics, and the most comprehensive list of business software.","email":"info@capterra.co.uk","url":"https://www.capterra.co.uk/","logo":"https://dm-localsites-assets-prod.imgix.net/images/capterra/logo-a9b3b18653bd44e574e5108c22ab4d3c.svg","@id":"https://www.capterra.co.uk/#organization","@type":"Organization","parentOrganization":"Gartner, Inc.","sameAs":["https://twitter.com/Capterra","https://www.facebook.com/Capterra/","https://www.linkedin.com/company/capterra/","https://www.youtube.com/channel/UCEt7vQSPiPlPAblHdhJAqnA"]},{"name":"Capterra UK","url":"https://www.capterra.co.uk/","@id":"https://www.capterra.co.uk/#website","@type":"WebSite","publisher":{"@id":"https://www.capterra.co.uk/#organization"},"potentialAction":{"query":"required","target":"https://www.capterra.co.uk/search/?q={search_term_string}","@type":"SearchAction","query-input":"required name=search_term_string"}},{"name":"What is ethical hacking and how it can help your business","description":"In this article, we explore what is ethical hacking and how it can help small businesses protect themselves from cyberattacks.","url":"https://www.capterra.co.uk/blog/1620/what-is-ethical-hacking-help-your-sme","about":{"@id":"https://www.capterra.co.uk/#organization"},"@id":"https://www.capterra.co.uk/blog/1620/what-is-ethical-hacking-help-your-sme#webpage","@type":"WebPage","isPartOf":{"@id":"https://www.capterra.co.uk/#website"}},{"description":"Last year, more than 1.4 million SMEs in the UK were affected by a cyberattack,  costing the UK economy £8.8 billion overall. And with  over half of the British workforce working from home due to the COVID-19 pandemic, making sure your business is in safe hands is more relevant than ever. ","author":[{"name":"Sonia Navarrete","@type":"Person"}],"image":{"url":"https://images.ctfassets.net/63bmaubptoky/NlQDIV23RIPO9_2q4Qgtr3aCf14p6CJabcYM849E7nY/b3c9a22e66abc0343fb197fe300a80c0/James-Bond.png","@id":"https://www.capterra.co.uk/blog/1620/what-is-ethical-hacking-help-your-sme#primaryimage","@type":"ImageObject"},"@type":"BlogPosting","articleBody":"&lt;p&gt;Last year, more than 1.4 million SMEs in the UK &lt;a href=&quot;https://www.techradar.com/uk/news/cyberattacks-costing-uk-smes-billions-every-year&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;were affected by a cyberattack&lt;/a&gt;,  costing the UK economy £8.8 billion overall. And with &lt;a href=&quot;/blog/1471/key-takeaways-from-uk-going-remote&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt; over half of the British workforce working from home&lt;/a&gt; due to the COVID-19 pandemic, making sure your business is in safe hands is more relevant than ever. &lt;/p&gt;&lt;img title=&quot;James-Bond&quot; alt=&quot;ethical-hacking&quot; class=&quot;aligncenter&quot; fetchpriority=&quot;high&quot; src=&quot;https://images.ctfassets.net/63bmaubptoky/NlQDIV23RIPO9_2q4Qgtr3aCf14p6CJabcYM849E7nY/b3c9a22e66abc0343fb197fe300a80c0/James-Bond.png&quot; srcset=&quot;https://images.ctfassets.net/63bmaubptoky/NlQDIV23RIPO9_2q4Qgtr3aCf14p6CJabcYM849E7nY/b3c9a22e66abc0343fb197fe300a80c0/James-Bond.png?w=400 400w, https://images.ctfassets.net/63bmaubptoky/NlQDIV23RIPO9_2q4Qgtr3aCf14p6CJabcYM849E7nY/b3c9a22e66abc0343fb197fe300a80c0/James-Bond.png?w=700 700w, https://images.ctfassets.net/63bmaubptoky/NlQDIV23RIPO9_2q4Qgtr3aCf14p6CJabcYM849E7nY/b3c9a22e66abc0343fb197fe300a80c0/James-Bond.png?w=1000 1000w, https://images.ctfassets.net/63bmaubptoky/NlQDIV23RIPO9_2q4Qgtr3aCf14p6CJabcYM849E7nY/b3c9a22e66abc0343fb197fe300a80c0/James-Bond.png?w=1500 1500w, https://images.ctfassets.net/63bmaubptoky/NlQDIV23RIPO9_2q4Qgtr3aCf14p6CJabcYM849E7nY/b3c9a22e66abc0343fb197fe300a80c0/James-Bond.png?w=2200 2200w&quot; sizes=&quot;(min-resolution: 2x) 2200px, (min-width: 992px) 1000px, 95vw&quot;/&gt;&lt;p&gt;Since the beginning of the lockdown in the UK, more than &lt;a href=&quot;/blog/1537/cyber-attack-increase-in-phishing-due-to-coronavirus&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;30% of SMEs have been victims of phishing emails&lt;/a&gt;, and almost half of those emails (45%) are related to COVID-19. &lt;/p&gt;&lt;p&gt;In this article, we will explore:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;What is ethical hacking? &lt;/li&gt;&lt;li&gt;How it can help small businesses protect themselves from cyberattacks and hacking.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;What is ethical hacking?&lt;/h2&gt;&lt;p&gt;According to the Cambridge English Dictionary, a &lt;a href=&quot;https://dictionary.cambridge.org/dictionary/english/hacker&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;hacker is a person&lt;/a&gt; “&lt;i&gt;who is  skilled in the use of  computer systems , often one who  illegally obtains access to  private computer systems&lt;/i&gt;.” &lt;/p&gt;&lt;p&gt;Now, imagine a person whose business is also  hacking private systems and data but to keep them safe instead.&lt;/p&gt;&lt;p&gt;This is the figure of the  ethical hacker or ‘ white hat ’  hacker , someone who is trusted by the company to attempt to enter the organisation’s networks and systems carrying  penetration testing and an  ethical hack – and most times is a &lt;a href=&quot;https://www.itgovernance.co.uk/shop/product/certified-ethical-hacker-ceh-training-course&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Certified Ethical Hacker&lt;/a&gt;. &lt;/p&gt;&lt;p&gt;Both have the same knowledge, but the difference is that the ethical hacker is on the side of the law (and the company). &lt;/p&gt;&lt;p&gt;An  ethical hacker performs the  hacking of a company using the same techniques than a  hacker would to test the company’s  cybersecurity measures and help them improve them against real attacks.&lt;/p&gt;&lt;p&gt;Hiring an ethical hacker has been something that traditionally was seen as something that only large corporations could (and needed) to do. &lt;/p&gt;&lt;h2&gt;The value of identifying threats in advance&lt;/h2&gt;&lt;p&gt;One of the ways in which companies are strengthening their cybersecurity is by hiring white hat hackers or ethical hackers. &lt;/p&gt;&lt;p&gt;Ethical hackers have a similar skill set as ‘ black hat ’ (malicious) hackers, and are able to find  vulnerabilities in your system via  penetration testing and  hacking into your system, with the flip side that they can also advise you on how to best prepare to avoid these.&lt;/p&gt;&lt;p&gt;As threats become more sophisticated, companies need to look at other ways to defend themselves from these threats. In 2019, &lt;a href=&quot;https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/813599/Cyber_Security_Breaches_Survey_2019_-_Main_Report.pdf&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;60% of the companies hacked&lt;/a&gt; were medium-sized businesses. &lt;/p&gt;&lt;p&gt;The Cyber Security Breaches Survey report issued by the government, also states that despite this figure, the number of &lt;a href=&quot;https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/813599/Cyber_Security_Breaches_Survey_2019_-_Main_Report.pdf&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;businesses identifying cyber security breaches&lt;/a&gt; has decreased since 2017.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Harman Singh, Managing Consultant at Defendza, &lt;/b&gt;explains the reasons why some SMEs fail to act on cyber security:&lt;/p&gt;&lt;p&gt;&lt;i&gt;“Some SMEs have a lack of proactive approach towards cyber security to ensure it is an organisation-wide priority. They also don’t see compliance as a priority and they rely on the IT services provider to take care of security without involving a specialist skill set.&lt;/i&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;Several small businesses have experienced cyber attacks, and the majority of them are unaware. Digital revolution in recent years has exposed our professional and personal life, and it is essential that businesses are ready against potential threats.”&lt;/i&gt;&lt;/p&gt;&lt;h2&gt;Keep your company safe from attackers&lt;/h2&gt;&lt;p&gt;However, if hiring an ethical hacker is not in the cards for you, the &lt;a href=&quot;https://www.ncsc.gov.uk/section/information-for/small-medium-sized-organisations&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;National Cyber Security Centre&lt;/a&gt; (NCSC) provides guidance to organisations to ensure these use best practices to keep the information secure. &lt;/p&gt;&lt;p&gt;Below we have listed four tips to make sure your data is in safe hands.&lt;/p&gt;&lt;h3&gt;&lt;b&gt;1. Awareness&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;You can have the most sophisticated system in place, hire an ethical hacker, and security applications, but unless your staff knows good security practices, it’s not worth it. Therefore training your staff is key, as well as making sure that they understand the real implications of an attack. &lt;/p&gt;&lt;p&gt;The UK Government offers &lt;a href=&quot;https://www.gov.uk/government/collections/cyber-security-training-for-business&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;free online training for small and medium-sized businesses&lt;/a&gt; that helps employees understand the importance of cybersecurity and also provides practical tips to help them identify threats. &lt;/p&gt;&lt;h3&gt;&lt;b&gt;2. Keep your devices safe&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;Smartphones and tablets are critical, but vulnerable devices used by businesses. It’s vital to secure them because they could contain sensitive company data or provide a backdoor into the company’s network.  The NCSC &lt;a href=&quot;https://www.ncsc.gov.uk/collection/small-business-guide/keeping-your-smartphones-and-tablets-safe&quot; rel=&quot;nofollow noopener noreferrer&quot; target=&quot;_blank&quot;&gt;provides some tips for small businesses&lt;/a&gt; such as keeping devices and the apps up to date to make sure the latest security update is installed in the device. &lt;/p&gt;&lt;h3&gt;&lt;b&gt;3. Passwords&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;The &lt;a href=&quot;https://www.ncsc.gov.uk/collection/small-business-guide/using-passwords-protect-your-data&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;NCSC also recommends training your staff&lt;/a&gt; into best practices with passwords such as choosing the right length and tips on storing it.  Having a strong password is a must. &lt;a href=&quot;/directory/30923/password-management/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Password management software &lt;/a&gt;can help with securing and storing passwords, keeping them in a digital vault. &lt;/p&gt;&lt;h3&gt;&lt;b&gt;4. Backup&lt;/b&gt;&lt;/h3&gt;&lt;p&gt;As well as all of the above tips, it is also important to back up your data regularly. &lt;a href=&quot;/directory/31076/backup/software&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Backup software&lt;/a&gt; creates copies of the data that can be restored in case of a breach or a data loss.&lt;/p&gt;&lt;p&gt;The &lt;a href=&quot;https://www.ncsc.gov.uk/collection/small-business-guide/backing-your-data&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;NCSC recommends keeping data separate&lt;/a&gt; from the computer and considering the cloud, as the data is physically separate from the computer and also offers backup services at a lower cost and without having to invest in hardware.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/nehammond/&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;Neil Hammond &lt;/b&gt;&lt;/a&gt;gives some tips to keep your company’s cyber security updated:&lt;/p&gt;&lt;p&gt;&lt;i&gt;“Make sure that your staff is trained. There is plenty of material available to help with staff education, especially if it is done as “this will help you stay cyber-secure at home”. &lt;/i&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;Also, keeping software up to date is important because reputable suppliers regularly patch their software for vulnerabilities. &lt;/i&gt;&lt;/p&gt;&lt;p&gt;&lt;i&gt;Finally, it is critical to keep good backups. A 3-2-1 strategy means having at least 3 total copies of your data, 2 of which are local but on different devices (for example 1 on memory stick and 1 on hard drive), and at least 1 copy offsite (and not connected directly to your main files).”&lt;/i&gt;&lt;/p&gt;&lt;div class=&quot;box-idea&quot;&gt;Looking for cyber security software? Check out our &lt;a href=&quot;/directory/31037/cybersecurity/software&quot; rel=&quot;noopener noreferrer&quot; class=&quot;evnt&quot; data-evac=&quot;ua_click&quot; data-evca=&quot;Blog_idea&quot; data-evna=&quot;engagement_blog_product_category_click&quot; target=&quot;_blank&quot;&gt;cyber security software&lt;/a&gt; or &lt;a href=&quot;/directory/31076/backup/software&quot; rel=&quot;noopener noreferrer&quot; class=&quot;evnt&quot; data-evac=&quot;ua_click&quot; data-evca=&quot;Blog_idea&quot; data-evna=&quot;engagement_blog_product_category_click&quot; target=&quot;_blank&quot;&gt;backup software&lt;/a&gt; catalogue.&lt;/div&gt;&lt;p&gt;&lt;/p&gt;","dateModified":"2023-11-06T13:27:06.000000Z","datePublished":"2020-06-04T08:00:08.000000Z","headline":"What is ethical hacking and how can it help your business","inLanguage":"en-GB","mainEntityOfPage":"https://www.capterra.co.uk/blog/1620/what-is-ethical-hacking-help-your-sme#webpage","publisher":{"@id":"https://www.capterra.co.uk/#organization"}}]}
</script>
