All professional firms
Vulnerability scan or penetration test: which does your firm need?
· PS ProTech · 3 min read
A client's security questionnaire asks: "Do you perform regular vulnerability scanning and annual penetration testing?" Many firms tick yes to both without being sure what either is. They're different things, and the difference matters when someone asks for the report.
A vulnerability scan
A scan is automated. Software checks your computers, network equipment and anything facing the internet against a catalogue of known weaknesses: missing updates, outdated software, risky settings, open doors that shouldn't be.
It produces a list, ranked by seriousness. Think of it as walking round the building checking which windows are unlocked.
- How often: monthly or quarterly, and after any big change.
- Disruption: almost none.
- What you get: a list of known weaknesses to fix.
Its limit is that it only finds what's in the catalogue, and it doesn't tell you whether a weakness can be used to reach anything that matters.
A penetration test
A penetration test is done by a person. A tester, with your written permission, tries to break in the way an attacker would, and then tries to go further: from one computer to another, from a staff account to an administrator's, from the network to the client files.
It answers a different question. A scan asks "what's unlocked?" A test asks "starting from nothing, how far could someone get?"
- How often: usually once a year, or after major changes.
- Disruption: some planning, little interruption if done well.
- What you get: a report showing what the tester reached, how, and what to fix first.
A good test often finds problems no scan would: a weak password on an old account, a shared folder open to everyone, a way to turn two small flaws into one large one.
Which do you need?
Start with scanning. It's inexpensive, it's regular, and there's little point paying a person to find missing updates a tool would have found. Fix what the scans show first. Keeping software current removes most of it, as we explain in why software updates matter.
Add a penetration test when:
- A client contract or security questionnaire requires one.
- Your insurer asks for it.
- You hold highly sensitive information and want to know your real exposure.
- You've made big changes: a new office, a new system, a move to the cloud.
What to ask before you buy a test
- Is it a real test or a scan with a cover page? Some "penetration tests" are an automated scan relabelled. Ask whether a person does the work and what they'll attempt.
- What's in scope? Only what faces the internet, or the inside of your network too? Email and cloud accounts?
- Will they test your people? Some tests include phishing your staff, with your agreement.
- What does the report look like? You want plain-language findings and a priority order, not two hundred pages of output.
- Is a retest included? So you can show the problems were fixed.
Using the results
Both produce a to-do list, and the value is in doing it. Assign each finding to a person with a date, fix the serious ones first, and keep the report with a note of what was done.
That file is what a client or insurer wants to see. The report alone shows you looked. The report plus the fixes shows you acted, which is the point of what cyber insurers ask and of most client security questionnaires.
We offer both as extras on any plan, priced after a short conversation about what you need tested. See vulnerability scanning and penetration testing, or raise it in a free IT and cybersecurity review.
