Penetration testing vs vulnerability scanning — what is the difference?
A scanner identifies potential vulnerabilities. A penetration tester determines whether they can actually be exploited, chained together and used to reach a meaningful target.
Vulnerability scanning and penetration testing answer different questions. An automated scanner looks for known issues based on software versions, configurations and service responses. A pentest uses that information as one input, but goes further.
What does vulnerability scanning provide?
It is fast, repeatable and useful for regularly checking large numbers of assets. It works well as part of an ongoing vulnerability-management process. The results still require validation because scanners can produce false positives and can miss issues that require context or manual reasoning.
What does a penetration tester do?
A penetration tester analyses the environment from an attacker’s perspective while staying within an agreed scope and rules of engagement. The goal is not only to identify one flaw, but to determine whether several smaller weaknesses can be chained into a meaningful attack path.
- authentication and authorisation weaknesses,
- excessive privileges,
- web application and API vulnerabilities,
- configuration of internet-facing services,
- privilege escalation and lateral movement opportunities,
- the effect of a successful attack on data and business processes.
Why scope and rules of engagement matter
A pentest should define target systems, permitted techniques, windows for higher-risk activity, emergency contacts and a stop procedure. The aim is not to prove that something can be broken, but to obtain useful evidence of real risk in a controlled way.
When should you run a pentest?
Consider one before launching a critical application, after major infrastructure changes, after changes to authentication or authorisation, and periodically for internet-facing systems that are important to business operations.
Want to apply this to your own environment?
We can start with a short conversation and identify the areas worth checking first.
Book a call