Penetration Test vs Vulnerability Scan

They sound similar and get sold interchangeably — but they’re very different jobs, and buyers increasingly reject one dressed up as the other. Here’s the honest difference, and which you actually need.

Vulnerability scan
Automated, known issues
Penetration test
Manual, real exploitation
A scan takes
Minutes to hours
A pen test takes
Days, by a person

The core difference

A vulnerability scan is an automated tool that checks your systems against a database of known issues and misconfigurations. It’s fast, cheap and repeatable — you can run it weekly — and it’s good at catching missing patches and obvious mistakes at scale. What it can’t do is think.

A penetration test is a qualified human attacking your systems the way a real adversary would: chaining several small issues into a genuine compromise, exploiting business logic a scanner has no concept of, and judging what actually matters. A scanner lists 200 ‘findings’; a tester tells you the three that would get you breached and how they’re linked.

Where a scan falls short

Scanners miss the things that cause real breaches: access-control flaws (seeing another user’s data by changing an ID), authentication bypasses, chained exploits, and any logic specific to your application. They also produce false positives that take expertise to sort from real risk. That’s why buyers, insurers and tenders increasingly won’t accept scan output presented as a penetration test.

Which do you need?

Most organisations need both, doing different jobs. Run vulnerability scanning continuously to keep on top of patching and drift. Commission a penetration test periodically — at least annually and after significant change — for the depth a scanner can’t reach and the evidence buyers ask for. If a quote for a ‘penetration test’ looks suspiciously cheap, it’s usually a scan with a report template around it.

Common questions

Is a vulnerability scan good enough for a tender?

Rarely. If the requirement says ‘penetration test’, buyers increasingly expect manual testing by an accredited tester, not automated scan output. A scan is a useful ongoing hygiene tool, not a substitute for a test.

Can't I just run a scanner myself?

You can, and it’s worth doing for ongoing hygiene. But interpreting the results, weeding out false positives and finding what a scanner can’t see is where a tester earns their keep — and it’s what a real assessment of your risk requires.

Why is a penetration test so much more expensive?

Because it’s skilled human time rather than an automated tool. A tester spends days manually probing, chaining and exploiting, then explains what matters. That effort is exactly what finds the issues that actually get organisations breached.

Related

Not sure which you need?

Tell us what you’re trying to achieve — a tender, an insurer, or genuine assurance — and we’ll tell you honestly whether it’s a scan, a test, or both.