Plenty of UK businesses have bought a penetration test and received a vulnerability scan with a cover page. The two are sold interchangeably, priced very differently, and answer completely different questions.

Neither is better. They are different instruments, and buying the wrong one wastes money twice: once on the thing you did not need, and again when you buy the thing you did.

14 daysCyber Essentials deadline for high and critical patches
HumanWhat a penetration test brings that no scanner does
BothWhat mature security programmes actually run

The one sentence version

A vulnerability assessment answers: what security issues exist across our estate? Outdated software, missing patches, unsupported operating systems, weak or default configurations, exposed services, expiring certificates.

A penetration test answers: what can a skilled person actually do with them? It is human thinking applied to your systems: exploiting weaknesses, chaining them together, and finding the complex issues no scanner is built to recognise.

The first is breadth, run repeatedly. The second is depth, applied by someone whose job is to think like the attacker. Confusing them is how a business ends up with a 200 page report full of findings nobody can act on, or a beautifully written narrative about one clever attack path while forty unpatched systems sit untouched.

Side by side

Vulnerability assessmentPenetration test
Question answeredWhat security issues exist across the estate?What can a skilled attacker actually achieve?
MethodAutomated scanning across everything in scope, validated by a humanA qualified tester exploiting weaknesses and chaining them, using judgement a tool does not have
CoverageBroad. Everything in scope, every timeFocused. Depth over breadth, guided by what is actually reachable
OutputA prioritised list of findings, with false positives removedA narrative of what was achieved, with evidence, plus the findings that enabled it
FrequencyContinuous or monthly, because the estate changesPeriodic, and after significant change
Answers “are we secure?”Partly. It tells you what is visibleMore convincingly, but only for what was in scope on the day
Typical costLower, and scales with the size of the estateHigher, and scales with complexity and time

What a vulnerability assessment does well

It finds security issues at scale, repeatedly and cheaply. In practice that means:

  • missing security patches, rated by severity;
  • operating systems and applications past their vendor support date;
  • default, weak or insecure configurations;
  • services exposed to the internet that should not be;
  • unencrypted protocols and expiring or invalid certificates;
  • known vulnerable software versions, matched against public vulnerability databases.

It does this across everything in scope rather than sampling, and as often as you like.

That last point is the one businesses undervalue. Your estate changes weekly: new devices, new services, new versions with new flaws. A scan run once a year describes a network that no longer exists. Scanning regularly is what turns it from a snapshot into a control.

The limitation is judgement. A scanner reports what it recognises, rates it by a generic severity score, and has no idea whether the affected system holds your customer database or runs the coffee machine. That is why validation matters: unvalidated scanner output is a list of possibilities, not a list of problems.

How a vulnerability programme keeps you certified

This is the part most businesses miss, and it is the strongest practical argument for running assessments continuously rather than once.

Cyber Essentials requires that security updates rated high or critical by the vendor are applied within 14 days of release. That is not a target; it is a condition of certification, and it applies every day of the twelve months your certificate is valid, not just on the day you were assessed.

Nobody meets that requirement by memory. Meeting it needs a process that tells you, on an ongoing basis:

  • which systems are missing high or critical updates right now;
  • how long each has been outstanding against the 14 day clock;
  • which software has fallen out of vendor support and therefore cannot remain in scope at all;
  • what changed since the last scan, because the estate changes weekly.

That is precisely what a vulnerability management programme produces. It turns the patching requirement from an annual scramble before assessment into a routine you can evidence, and it surfaces unsupported software months before it becomes a certification problem rather than a fortnight before a renewal deadline.

It has a second benefit at renewal. When someone asks how you know you are meeting the 14 day requirement, “we scan continuously and here is the trend” is a considerably better answer than “we think so”. Our guide to Cyber Essentials renewal covers what else changes between years.

What a penetration test does well

It tells you what a capable human can actually do, which is almost never what the severity scores suggest.

Real attacks are chains. A medium severity information disclosure gives up a username format; an unenforced policy allows password spraying; one account has more access than anyone realised; that access reaches the file server. Four findings, none of them critical alone, one serious breach. No scanner assembles that chain, because a scanner evaluates findings individually and has no concept of what they add up to. A tester does, and demonstrates it with evidence.

More importantly, a test finds the complex issues scanners are not built to detect at all:

  • Business logic flaws. Changing an order quantity to a negative number, skipping a payment step, or approving your own request. The application works exactly as coded; the code is simply wrong about how the business works.
  • Broken access control between accounts. Changing a record identifier in a URL and seeing another customer’s data. Every individual component is patched and correctly configured.
  • Privilege escalation paths. A service account with more rights than anyone intended, a scheduled task running as an administrator, a share that should not be writable.
  • Chained misconfigurations. Each setting defensible alone, dangerous in combination.
  • Assumptions that do not hold. The developer who assumed the field would only ever contain a number; the administrator who assumed nobody would find that host.

Scanners look for known signatures of known problems. Testers look for the problem nobody has documented yet, which is exactly the kind an attacker interested in your business specifically will go hunting for.

The limitation is scope and time. A test covers what was agreed, during the window agreed, in the state the environment was in that week. It is a deep look at part of the picture, not a guarantee about all of it.

The buying test

If you need to know what security issues exist across everything you own, and to keep meeting the 14 day patching requirement, buy a vulnerability assessment and run it continuously. If you need to know what a skilled person could actually achieve against a specific system, buy a penetration test. If a proposal for one is priced like the other, ask which of those two questions it answers.

How to tell what you are actually being sold

Four questions separate a genuine test from a scan in a suit:

“Who runs it, and what are their qualifications?” A penetration test is delivered by a qualified human. Ask who, and what certification they hold. Ours are certified through The Cyber Scheme.

“What proportion is manual?” Every real test starts with automated reconnaissance, which is fine and sensible. If the answer is “the tooling handles it”, you are buying a scan.

“What does the report contain besides findings?” A test report should describe what was attempted, what succeeded, what failed, what it means for the business, and what to do first. A list sorted by severity score is scanner output.

“Is retesting included?” Fixing findings is the point. A provider who charges again to verify remediation is selling a document rather than an outcome.

Sequencing: what to buy first

For most UK businesses that have never done either, the order is deliberately unglamorous.

Start with the basics being right at all, which is what Cyber Essentials covers. Then run a vulnerability assessment continuously, so you see the estate as it actually is and stay inside the 14 day patching requirement rather than rediscovering it each year. Then commission a penetration test against what matters most, so the tester spends their time on business logic and attack paths rather than telling you about missing patches you already knew about.

Buying a penetration test before the fundamentals are handled is paying a specialist day rate for findings a scan would have given you in an hour. Buying only scans forever means never learning what a person could do with what they found. Mature programmes run both, at different frequencies, for different reasons.

Not sure which you need?

That is a reasonable position, and it is a conversation rather than a sale. Get in touch or call 01722 445972, and we will tell you which of the two your situation calls for, including when the answer is neither yet.