Skip to content
Zyberum Cyber Security Firm
Menu
ComparisonsPenetration testing

Penetration Test vs Vulnerability Scan: What Each Finds and When to Use Which

A vulnerability scan finds known weaknesses automatically; a penetration test finds what a scanner cannot. Differences in depth and cost, and when to use which.

Updated This page as Markdown

In short

A vulnerability scan is an automated check of systems against a database of known weaknesses: fast, cheap, repeatable, and blind to logic flaws, chained attacks and anything without a signature. A penetration test is a human attacker with a scope and a deadline: it finds authorisation bugs, business-logic abuse and attack chains, costs days instead of minutes, and is what regulations and customers usually mean by "security test". Most organisations need both: scans continuously, pentests once or twice a year and after major changes.

What is the difference?

A vulnerability scan asks “does this system have a weakness I know about?”. A penetration test asks “how would an attacker get in, and how far would they get?”. The first is answered by software comparing versions, configurations and responses against a database. The second is answered by a person who reads the application, forms hypotheses and tries them, using scanners as one of many tools.

The results differ accordingly. A scan produces a long list of possible issues, many of them informational or false positives, each with a CVSS score copied from a database. A penetration test produces a shorter list of confirmed findings with proof, a severity judged in context, the chain they form and a fix recommendation for each.

Side by side

Vulnerability scanPenetration test
Who does itSoftware, scheduledSecurity engineers, with a scope and rules of engagement
FindsKnown CVEs, missing patches, weak TLS, default credentials, misconfigurations with a signatureAuthorisation flaws, business-logic abuse, injection in custom code, attack chains, weak crypto use, hardware and protocol weaknesses
MissesLogic flaws, anything without a signature, chained attacks, authenticated flows it cannot navigateWhatever lies outside the agreed scope and time
False positivesCommon; someone has to triageRare; every finding is reproduced
DurationMinutes to hoursDays to weeks
Typical costHundreds to a few thousand euros per year3,000 to 45,000 euros per test, depending on the target
FrequencyContinuous or weeklyOnce or twice a year and after major changes
Required byISO 27001 controls, PCI DSS (quarterly scans), many customer questionnairesPCI DSS (yearly), TISAX and many OEM requirements, NIS2 risk management in practice, CRA conformity assessment evidence, customer contracts
OutputFinding list with generic textReport with reproduction, context, chains and fixes; often a presentation and a retest

Choose a vulnerability scan when

  • You need to know, continuously, whether a known weakness appeared in your estate: a new CVE, an unpatched host, a certificate about to expire.
  • You run many systems and need coverage more than depth.
  • You have to show a compliance framework that scanning happens (PCI DSS asks for quarterly scans by an approved vendor).
  • Your budget is small and you have nobody to triage pentest findings yet. Fix what the scanner shows first; a pentest on an unpatched system wastes the tester’s time on things a scanner finds for free.

Choose a penetration test when

  • The system has accounts, roles, money or personal data: the interesting bugs are in logic and authorisation, where scanners are blind.
  • It is a product you ship: an IoT device, a machine, an ECU, an app. Scanners have little to say about firmware, debug ports, radio protocols or CAN.
  • A customer, an OEM, an auditor or a regulation asks for a test with a report and a named tester.
  • Before a launch, after a major rewrite, after a change of hosting or identity provider, or after an incident.

Both together

The sensible setup for most companies is a scanner that runs continuously and a penetration test once a year, plus one after major changes. The scan catches the known and the regressions; the pentest catches what only a person finds. Give the tester the scan results: it saves time on the obvious and lets the days go into the hard parts.

Zyberum does penetration tests and can set up scanning for you as part of the Zyberdome managed SOC; we do not sell scanners on their own. If what you need is a scan, say so and we will tell you which tool to use.

FAQ

Frequently asked questions

Is a vulnerability scan with a report a penetration test?

No, even if the offer calls it one. A scan report lists findings from a signature database with generic descriptions. A penetration test report shows what the tester did, which findings were confirmed by exploitation, how they chain together and what exactly to fix. If an offer for a "pentest" is priced in hours and delivered in a day, it is a scan.

Can I skip pentests if I scan continuously?

Only if nobody requires one and your application has no logic worth abusing. Scanners do not log in, do not understand roles, do not notice that user A can read user B’s data and do not chain findings. For anything with accounts, money or personal data, a yearly pentest is the minimum; the scan covers the time in between.

What does each cost?

A scanner licence or service costs from a few hundred euros per year for a handful of hosts to a few thousand for a company. A penetration test of a typical web application costs 6,000 to 15,000 euros, an IoT product 15,000 to 30,000 euros, typical market ranges for Germany and the EU. The scan is a fixed cost, the pentest is a project.

Sources

Related pages

Get started

Not sure which test you need?

Describe your product or environment in a 15-minute call. You get a clear recommendation and, if you want one, a fixed-price offer.

  • A recommendation, not a sales pitch
  • Scope and effort estimate on the spot
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usGet a recommendation

Pick a time that suits you

Open in a new tab