Vulnerability scanning and penetration testing both reduce cyber risk, but they answer different questions. A scan asks which known weaknesses and misconfigurations appear on the systems you pointed the tool at. A penetration test asks whether a skilled attacker can actually exploit weaknesses, chain them, and cause meaningful impact against an agreed objective. Confusing the two is how organisations buy a cheap PDF, then discover too late that an auditor, insurer or NHS buyer wanted something deeper.
This guide is for UK security, IT and procurement leads who need a clean commercial distinction: when scanning is enough, when a pentest is required, how the costs differ, and how to use both in a programme that holds up under scrutiny.
In short
- Scanning: frequent, automated, broad coverage of known issues; higher false-positive noise.
- Penetration testing: periodic, human-led, deeper exploitability and impact analysis; higher cost per engagement.
- Scans support hygiene. Tests support assurance conversations (boards, buyers, insurers, compliance evidence).
- A scan report is not a penetration test, even if someone renames the file.
- Most mature programmes run both on different cadences.
Context: two tools, one risk register
Neither activity replaces patching, identity hygiene, secure development or incident response. Both feed the same backlog: identify weaknesses, then let the business prioritise remediation. Attack Vector’s role in a test engagement is to find and evidence issues clearly. Your organisation owns the fixes.
Buyers get into trouble when a supplier sells scanner output as “annual penetration testing” at a suspiciously low fixed price. The reverse mistake also happens: commissioning an expensive pentest every month when a well-run scan programme would have caught the same missing patches sooner and cheaper.
Side-by-side comparison
| Feature | Vulnerability scanning | Penetration testing |
|---|---|---|
| Nature | Automated discovery of known weaknesses and misconfigurations | Human-led simulation of attacker behaviour against an agreed scope |
| Primary goal | Find known issues quickly and repeatedly | Prove exploitability, chaining and business impact |
| Human involvement | Mostly tooling; humans triage results | Skilled testers using tools plus manual techniques |
| Depth | Inventory of potential issues | Validated findings, attack paths, impact narrative |
| False positives | Common; need triage | Fewer; findings are usually validated |
| Typical frequency | Weekly, monthly or continuous for many estates | Annually, after major change, or before key assurance events |
| Relative cost | Lower per cycle | Higher per engagement |
| Best for | Hygiene, patch validation, broad coverage | Assurance evidence, complex apps, realistic risk stories |
What vulnerability scanning actually does
A vulnerability scanner fingerprints services, compares them against vulnerability databases, and flags missing patches, weak protocols, default credentials (in some configurations) and common misconfigurations. Authenticated scanning improves coverage for internal hosts. External scanning helps catch internet-facing exposure.
Done well, scanning is operational security work:
- Regular coverage across large estates
- Trend data for patch latency
- Early warning when a new critical CVE hits systems you own
- Input for change control and vulnerability management SLAs
Done poorly, scanning becomes noise: thousands of untriaged findings, duplicated tickets, and a false sense that “we scanned, so we tested.”
Scanning does not reliably find business logic flaws, complex authorisation bugs, multi-step chaining, or social-engineering assisted paths. It also cannot judge whether a theoretical CVE is reachable in your architecture without human validation.
What penetration testing actually does
A penetration test starts with rules of engagement and a scope. Testers combine reconnaissance, tooling and manual techniques to pursue objectives such as unauthenticated access to sensitive data, privilege escalation, or lateral movement. On web and API work, that often includes authorisation testing across roles, injection classes, session handling and logic abuse. On infrastructure work, it may include remote service exploitation, identity paths and segmentation checks.
The valuable outputs are:
- Validated findings with evidence
- Severity that reflects real exploitability and impact in your context
- An executive summary non-specialists can use
- Remediation guidance your engineers can prioritise
- Optional retest evidence when you need closure for buyers or auditors
Lead consulting credentials at Attack Vector include Cyber Scheme Team Leader (CSTL), from The Cyber Scheme, and Chartered Cyber Security Professional (ChCSP), the UK Cyber Security Council's chartered title. Those individual credentials support confidence in delivery quality.
Commercial and compliance reality
When scanning is the right buy
- You need continuous or frequent visibility across many hosts
- You are measuring patch and configuration hygiene
- You already have a recent pentest and need interim monitoring
- Budget is limited and the immediate need is breadth, not depth
When a penetration test is the right buy
- A customer, insurer, ISO 27001 auditor or board wants independent assurance
- You are preparing NHS-facing evidence (for example DTAC technical security conversations or DSPT-related assurance)
- You ship a complex authenticated application or API
- You changed architecture significantly (new IdP, new cloud edge, major release)
- A previous “pentest” was clearly scan-only and failed scrutiny
Typical cost shape
Vulnerability scanning is usually a lower recurring cost (tool licence, managed scanning service, or internal ops time). Penetration testing is usually a scoped professional-services fee driven by days and attack surface. Attack Vector testing starts from £1,500 for tightly defined work. For broader pricing context, see the UK penetration test cost guide.
How mature UK programmes combine both
A practical pattern for many SMEs and mid-market organisations:
- Monthly or continuous external scanning of internet-facing assets, with triage ownership.
- Authenticated internal scanning on a sensible cadence for servers and critical endpoints.
- Annual (or change-triggered) penetration testing of the systems that matter for customers, compliance and revenue.
- Retest of Critical and High findings before major sales or assurance deadlines.
- Keep reports and tickets linked so evidence shows discovery, fix and verification, not only a one-off PDF.
That combination costs less than pretending every scan is a pentest, and it produces better risk decisions than a once-a-year test with nothing in between.
Buying the label, not the outcome
The main commercial failure mode is label substitution. Marketing copy says penetration test. The method is unauthenticated scanning. The report lacks reproduction detail. Severity is either everything-critical or nothing-useful. When a buyer asks for methodology, tester competence and evidence of manual validation, the engagement collapses.
The second failure mode is over-testing with no remediation capacity. An expensive pentest that produces fifty findings nobody will fix is worse governance than a smaller scoped test whose Critical items get closed and retested.
What neither approach guarantees
- Scanning and testing are complementary; neither replaces the other.
- We identify weaknesses; your organisation prioritises and performs remediation.
- No scan or test guarantees you will pass an audit, win a tender or obtain insurance cover.
- If a supplier cannot explain what was manual versus automated, assume you are buying a scan.
If you already know you need a human-led test, try the instant quote calculator or email [email protected]. For service options, start with penetration testing services, including web application and infrastructure testing.
FAQ
Can a vulnerability scan replace an annual penetration test?
Usually no, where a buyer, auditor or insurer asked for penetration testing. Scanning supports hygiene; it does not demonstrate the same exploitability and impact analysis.
Why do scans produce so many false positives?
Tools infer risk from banners, versions and signatures. Without human validation, many items are unreachable, mitigated or mis-scored in your environment.
How often should we scan versus pentest?
Many organisations scan frequently and pentest at least annually or after major change. Exact cadence depends on change rate, regulation and customer expectations.
Is authenticated scanning the same as an internal pentest?
No. Authenticated scanning improves detection of missing patches and misconfigurations. An internal pentest pursues attacker objectives such as privilege escalation and lateral movement.
Will Attack Vector remediate what you find?
No. Attack Vector identifies and evidences weaknesses so you can prioritise remediation. Fix ownership stays with your engineering and IT teams; retest can verify closure when scoped.
What should a proper pentest report include that a scan PDF often lacks?
Clear scope, methodology notes, validated evidence, contextual severity, impact narrative, remediation guidance and a path to retest. Engineers should be able to reproduce or understand the issue without guessing.
Suggested Resources
Ready to strengthen your security?
Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.