Penetration test vs vulnerability scan: what is the difference?
A scan and a pentest are not the same thing, and the gap between them is where real breaches happen. Here is what each one does, and when you need which.
"We had a scan done — aren't we covered?" It is a fair question, and the answer matters, because a vulnerability scan and a penetration test are genuinely different things. The gap between them is exactly where real breaches tend to live.
What a vulnerability scan does
A vulnerability scan is automated. A tool checks your systems against a database of known issues — missing patches, weak configurations, outdated software — and produces a list, usually ranked by severity.
Scans are fast, affordable and genuinely useful. Run regularly, they are a great way to keep on top of known problems at scale. But an automated tool has real limits:
- It reports issues in isolation, and cannot tell that two "medium" findings chain together into a full compromise.
- It does not understand your business logic — that this user should not be able to reach that data.
- It generates false positives and lacks the judgement to know which findings actually matter in your environment.
A scanner tells you what *might* be wrong. That is valuable, but it is not the whole picture.
What a penetration test does
A penetration test is a person. An experienced tester examines your environment by hand, thinks like an attacker, and chains findings together the way a real adversary would — then safely demonstrates genuine impact where a way in exists.
The output is not just a list. It is a clear account of what an attacker could actually achieve, which issues to fix first, and reproduction steps your team can follow. Crucially, a good tester reasons about *intent* and *context*: the exact things automation cannot do.
A scanner finds the unlocked window. A tester climbs through it, moves through the house, and shows you what is actually at risk.
So which do you need?
Both, ideally — they answer different questions. Regular scanning keeps you on top of known, published issues between engagements. Periodic penetration testing finds the deeper problems: logic flaws, chained weaknesses, and the exposures automation simply cannot reason about.
The mistake to avoid is buying one and believing you have the other. A scan is not a pentest, and a compliance tick-box that only requires a scan will not surface the issues that lead to the worst incidents.
How we test
Our infrastructure testing — external and internal — is hands-on and methodology-led, delivered by a tester who holds The Cyber Scheme's Team Leader infrastructure qualification (CSTL-INF), one of the certifications recognised by the NCSC against UK government standards. Web application testing follows the OWASP standards, with authenticated, role-aware testing that finds the logic flaws a scanner never will.
If you want to know what a real attacker could do — not just what a tool flags — get a fixed-price quote and we will scope the right test for your environment, not the biggest one.
Put this into practice.
Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.