Skip to main content
ethical-hacking

Lead Ethical Hacker

Lead Ethical Hacker. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBLead5 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Cybersecurity professionals who want to master penetration testing techniques
  • Information security officers responsible for the security posture of information systems
  • Information security team members seeking to deepen their offensive security knowledge
  • Managers or expert advisors who oversee or commission ethical hacking engagements
  • Technical experts who need to plan and execute structured penetration tests
  • Individuals pursuing a recognised ethical hacking qualification

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Beginners with no prior exposure to information security concepts, as the technical pace will be challenging without that foundation
  • Non-technical managers seeking only policy or governance knowledge, since the course is hands-on and technically intensive
  • Professionals focused purely on compliance auditing rather than active security testing
  • Individuals looking for a general IT overview rather than specialised offensive security skills

What you'll be able to do

  • 1Apply the core concepts, methods, and techniques that ethical hackers use when planning and executing penetration tests
  • 2Map penetration testing methodologies to relevant regulatory frameworks and industry standards
  • 3Conduct a structured reconnaissance phase to gather actionable intelligence about a target environment
  • 4Execute exploitation techniques against identified vulnerabilities using responsible, controlled methods
  • 5Perform post-exploitation analysis to evaluate the true impact of a successful compromise
  • 6Produce clear, evidence-based penetration test reports that communicate findings to both technical and non-technical stakeholders
  • 7Manage ethical hacking activities within an information security programme

Day by day

Day 1Introduction to Ethical Hacking
  • Ethical Hacking Fundamentals

    This module establishes the legal, ethical, and methodological foundations that distinguish authorised penetration testing from unauthorised intrusion.

  • Penetration Testing Frameworks and Standards

    Participants examine how recognised methodologies and regulatory frameworks shape the structure and scope of a penetration test.

  • Engagement Scoping and Rules of Engagement

    This module covers how to define test boundaries, obtain written authorisation, and set rules of engagement before any testing begins.

By end of day

  • Distinguish the legal and ethical boundaries that govern authorised penetration testing
  • Select an appropriate penetration testing methodology for a given engagement
  • Define the scope and rules of engagement for a planned test
Day 2Initiating the Reconnaissance Phase
  • Passive Reconnaissance Techniques

    Participants learn to gather target intelligence using open-source tools and public data sources without directly interacting with target systems.

  • Active Reconnaissance and Scanning

    This module covers network scanning, service enumeration, and fingerprinting techniques used to build a detailed picture of the target environment.

  • Vulnerability Identification

    Participants practise correlating gathered intelligence with known vulnerabilities to prioritise attack vectors before the exploitation phase.

By end of day

  • Collect and organise target intelligence using both passive and active reconnaissance methods
  • Enumerate network services and identify potential vulnerabilities in a target environment
  • Prioritise attack vectors based on reconnaissance findings
Day 3Initiating the Exploitation Phase
  • Exploitation Concepts and Tools

    This module introduces the tools and techniques commonly used to exploit identified vulnerabilities in a controlled, authorised context.

  • Web Application and Network Exploitation

    Participants explore exploitation techniques targeting web application weaknesses and network-level vulnerabilities.

  • Gaining and Maintaining Access

    This module addresses techniques for establishing initial access and maintaining a foothold within a target environment during an authorised test.

By end of day

  • Apply exploitation techniques responsibly against identified vulnerabilities
  • Demonstrate how attackers gain initial access through web application and network weaknesses
  • Establish a controlled foothold to support subsequent post-exploitation activities
Day 4Post-Exploitation and Reporting
  • Post-Exploitation Techniques

    Participants learn privilege escalation, lateral movement, and data exfiltration simulation techniques used to assess the real-world impact of a breach.

  • Covering Tracks and Clean-Up

    This module explains how to restore systems to their pre-test state and document all changes made during the engagement.

  • Penetration Test Reporting

    Participants practise writing structured reports that document findings, evidence, risk ratings, and remediation recommendations for different audiences.

By end of day

  • Evaluate the business impact of a successful compromise using post-exploitation analysis
  • Restore the test environment and document all changes made during the engagement
  • Produce a professional penetration test report with prioritised remediation guidance
Day 5Review and Exam Preparation
  • Course Consolidation and Key Concept Review

    This session revisits the most important concepts, techniques, and frameworks covered across the four preceding training days.

  • Practical Scenario Walkthrough

    Participants work through an end-to-end penetration testing scenario to reinforce the full methodology from scoping through reporting.

By end of day

  • Consolidate knowledge of the complete penetration testing lifecycle
  • Identify personal knowledge gaps to address before sitting any external certification exam

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Information gathering tools and techniques
  • Domain 2: Threat modeling and vulnerability identification
  • Domain 3: Exploitation techniques
  • Domain 4: Privilege escalation
  • Domain 5: Pivoting and file transfers
  • Domain 6: Reporting
  1. Determining the scope of ethical hacking
  2. Defining a penetration testing approach
  3. Performing the steps that should be followed during a penetration testing
  4. Defining the penetration testing criteria
  5. Evaluating penetration test scenarios and treatment options
  6. Using the methods that help increase the security of operation systems
  7. Reporting the penetration testing results

Certification Rules and Policies

  • Certification and examination fees are included in the price of the training course.
  • Participants will be provided with training course materials containing over 400 pages of information, practical examples, exercises, and quizzes.
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • Candidates who have completed the training course but failed the exam are eligible to retake the exam once for free within a 12 month period from the initial date of the exam.

Educational Approach

  • Includes theoretical and practical exercises to help participants acquire the required skills
  • Includes a laboratory environment that provides in-depth knowledge and practical experience
  • Encourages participants to communicate and engage in discussion and the completion of exercises
  • Encourages participants to complete the practical exercises, which serve as a preparation for and are similar to the tasks of the certification exam

Building Digital Trust through Ethical Hacking

digital trust

Buyers always ask

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

Do I need prior penetration testing experience to attend this course?+

No hands-on penetration testing experience is formally required, but the course moves at a technical pace. Participants are expected to bring solid information security knowledge, strong operating system skills, and familiarity with networking concepts.

Individuals who lack that technical background may find the content challenging to absorb fully and would benefit from foundational study before attending.

What topics are covered across the five days?+

The training spans ethical hacking fundamentals and legal context on day one, passive and active reconnaissance on day two, exploitation techniques on day three, and post-exploitation analysis plus professional report writing on day four.

Day five is dedicated to consolidating all topics through review and practical scenario work to reinforce the full penetration testing lifecycle.

Is this course relevant for managers who oversee penetration testing programmes but do not perform tests themselves?+

Yes. The course explicitly targets managers and expert advisors who are responsible for commissioning, planning, or overseeing ethical hacking activities. The content on scoping, rules of engagement, and reporting is directly applicable to those roles.

However, participants who are not comfortable with technical content such as scanning tools and exploitation frameworks may find some practical segments less immediately applicable to their day-to-day work.

How does this course relate to regulatory and compliance requirements?+

The course addresses the correlation between penetration testing methodologies and regulatory frameworks and standards, helping participants understand how structured testing supports broader compliance and risk management obligations.

It does not, however, serve as a compliance audit training programme. The focus remains on the technical and operational aspects of conducting authorised penetration tests.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.