Plenty of UK businesses have bought a penetration test and received a vulnerability scan with a cover page. The two are sold interchangeably, priced very differently, and answer completely different questions.
Neither is better. They are different instruments, and buying the wrong one wastes money twice: once on the thing you did not need, and again when you buy the thing you did.
The one sentence version
A vulnerability assessment answers: what is exposed?
A penetration test answers: what could someone actually do about it?
The first is breadth. The second is depth. Confusing them is how a business ends up with a 200 page report full of findings nobody can act on, or a beautifully written narrative about one clever attack path while forty unpatched systems sit untouched.
Side by side
| Vulnerability assessment | Penetration test | |
|---|---|---|
| Question answered | What weaknesses exist across the estate? | What could an attacker achieve with them? |
| Method | Automated scanning, validated by a human | A skilled tester attempting to exploit, chaining findings together |
| Coverage | Broad. Everything in scope, every time | Focused. Depth over breadth, guided by what is actually reachable |
| Output | A prioritised list of findings, with false positives removed | A narrative of what was achieved, with evidence, plus the findings that enabled it |
| Frequency | Continuous or monthly, because the estate changes | Periodic, and after significant change |
| Answers “are we secure?” | Partly. It tells you what is visible | More convincingly, but only for what was in scope on the day |
| Typical cost | Lower, and scales with the size of the estate | Higher, and scales with complexity and time |
What a vulnerability assessment does well
It finds things at scale, repeatedly, cheaply. Missing patches, exposed services, weak configurations, software past its support date, certificates about to expire. It does this across everything in scope rather than sampling, and it does it as often as you like.
That last point is the one businesses undervalue. Your estate changes weekly: new devices, new services, new versions with new flaws. A scan run once a year describes a network that no longer exists. Scanning regularly is what turns it from a snapshot into a control.
The limitation is judgement. A scanner reports what it recognises, rates it by a generic severity score, and has no idea whether the affected system holds your customer database or runs the coffee machine. That is why validation matters: unvalidated scanner output is a list of possibilities, not a list of problems.
What a penetration test does well
It tells you what a capable human can actually do, which is almost never what the severity scores suggest.
Real attacks are chains. A medium severity information disclosure gives up a username format; an unenforced policy allows password spraying; one account has more access than anyone realised; that access reaches the file server. Four findings, none of them critical alone, one serious breach. No scanner assembles that chain. A tester does, and demonstrates it with evidence.
A test also finds things scanners cannot see: business logic flaws, broken access controls between user accounts, workflows that can be manipulated, assumptions the developers made that do not hold.
The limitation is scope and time. A test covers what was agreed, during the window agreed, in the state the environment was in that week. It is a deep look at part of the picture, not a guarantee about all of it.
If you want to know what needs fixing across everything you own, buy a vulnerability assessment and run it regularly. If you want to know what someone determined could achieve against a specific system, buy a penetration test. If a proposal for one is priced like the other, ask exactly which of those two questions it answers.
How to tell what you are actually being sold
Four questions separate a genuine test from a scan in a suit:
“Who runs it, and what are their qualifications?” A penetration test is delivered by a qualified human. Ask who, and what certification they hold. Ours are certified through The Cyber Scheme.
“What proportion is manual?” Every real test starts with automated reconnaissance, which is fine and sensible. If the answer is “the tooling handles it”, you are buying a scan.
“What does the report contain besides findings?” A test report should describe what was attempted, what succeeded, what failed, what it means for the business, and what to do first. A list sorted by severity score is scanner output.
“Is retesting included?” Fixing findings is the point. A provider who charges again to verify remediation is selling a document rather than an outcome.
Sequencing: what to buy first
For most UK businesses that have never done either, the order is deliberately unglamorous.
Start with the basics being right at all, which is what Cyber Essentials covers. Then run a vulnerability assessment to see the estate as it actually is, and fix what it finds. Then commission a penetration test against what matters most, so that the tester spends their time on interesting problems rather than telling you about missing patches.
Buying a penetration test before the fundamentals are handled is paying a specialist day rate for findings a scan would have given you in an hour. Buying only scans forever means never learning what a person could do with what they found. Mature programmes run both, at different frequencies, for different reasons.
Not sure which you need?
That is a reasonable position, and it is a conversation rather than a sale. Get in touch or call 01722 445972, and we will tell you which of the two your situation calls for, including when the answer is neither yet.