Home › Resources › Penetration testing › Vulnerability scan or penetration test: which do you need?

Vulnerability scan or penetration test: which do you need?

A vulnerability scan is software that compares your systems against a catalogue of known weaknesses. A penetration test is a skilled person attacking your environment the way a genuine adversary would. Each answers a different question, and paying for the wrong one is money wasted.

Why it matters

Scanning tells you which known flaws are present. Testing tells you what an attacker could do with them: which ones chain together, which expose data, and which your defences would actually stop. Frameworks, insurers and tender questionnaires increasingly insist on testing because a scanner cannot find logic flaws, chained attacks or anything it has no signature for.

How to use each one

  • Run scanning continuously; it is inexpensive, repeatable and picks up known flaws early
  • Run penetration tests periodically and after major change, when real-world impact is the question
  • A proper test pairs automated tooling with methodical, hands-on analysis by a tester
  • Expect findings that are validated and evidenced, not simply listed
  • Treat the two as partners rather than alternatives; mature programmes do both

A quick way to decide

If your question is "which known weaknesses exist across our estate?", scan. If it is "could somebody get from the internet to our customer records, and would anyone notice?", that is precisely what a penetration test is built to answer. Boards, insurers and auditors generally want the second question answered, which is why most mature programmes run both.

Where Intelligence Group fits

Intelligence Group tests networks, applications, wireless and people across New Zealand and Australia, evidences every finding and retests once you have fixed it. See what we test or request a quote.