Menu

Call us on 03450 21 21 51

Vulnerability scan vs penetration test: which is right for your business
The SRM Blog

Vulnerability scan vs penetration test: which is right for your business

Dean Moulden

Written by Dean Moulden

9th May 2021

Share this article

vulnerability scan vs penetration test

SRM Senior Penetration Tester, Dean Moulden, explains why a combination of automated scanning tools and manual testing is the most efficient and effective way of assessing where a business’s digital strengths and weaknesses lie.

It’s a relatively common question from new clients: how and when should a vulnerability scan be used vs a penetration test to establish weaknesses in a business’s online defences. But before I tackle this topic, it’s worth briefly recapping on what a vulnerability scan and penetration test actually is.

 

The vulnerability scan

Also known as a vulnerability assessment, these automated scans evaluate computers, systems and networks for security weaknesses. The benefit of a vulnerability scan is obvious. It is quick, affordable and, because it is automated, it can be scheduled to run on a regular basis, monitoring vulnerabilities in network devices such as firewalls, routers, switches, servers and applications.

To give an example of the time-saving properties of the market-leading software we use at SRM: our scanner recently took four days to assess a client’s entire digital estate as part of a process that would have taken up to 20 days if it had been completed manually.

However, it is worth noting that scanning tools are designed to report on vulnerabilities that are already known to exist and can be readily detected. The scan is generally of a prescribed nature, in that it is checking for known issues and patches according to a database.

Importantly, it does not inform about the potential exploitation of vulnerabilities, about vulnerabilities that have not already been identified in the wild; nor does it exploit the vulnerabilities and demonstrate how fixes or patches can be implemented.

You can liken a vulnerability scan to a routine household security check: locating any open doors or windows and identifying them for further investigation. In this way, it can provide part of the story but it does not provide a complete picture.

 

The penetration test

To continue with the household analogy: a penetration test is like challenging a highly skilled expert to break into your home so that you might find out how to stop a real burglar in the future. They may emulate a real-life thief and use a variety of more devious ways to gain access than simply pushing on the front door. They may see if they can persuade one of your neighbours to give them a key, trick you into sharing the alarm code or even use brute force to smash a rear window.

As CREST certified pen testers we use a variety of strategies to gain access to a client’s system. This means using an array of tactics and techniques to probe a company’s digital defences and even exploit human vulnerabilities to see if team members might be weak links in the security chain. In simple terms, we replicate the same strategies that a real hacker or threat actor would to breach a business’s defences. This is why the term ‘ethical hacking’ is often used to describe experts in our line of work.

 

Vulnerability scan vs penetration test

At SRM, we typically advise organisations to think less in terms of which service they require and more about how to employ both services in the most meaningful yet cost-effective way.

To use the recent example I mentioned earlier, a vulnerability scan may save many hours of manual work. But more importantly, it will also flag areas of concern to our penetration testing team, enabling us to focus our more detailed and in-depth manual tests in the right areas.

This can include delving deeper into the security of a network, applications or the underlying operating system. And because it is a proactive approach, it is quite common for our penetration testers to exploit a new vulnerability or discover vulnerabilities that have not been previously known.

Having investigated these vulnerabilities rigorously we then prepare a detailed report that clearly presents both issues and potential solutions to a client.

While many organisations undertake annual penetration tests and vulnerability scans in order to ensure compliance with an information security framework, a growing number of businesses also recognise that combining these services allows them to assess and optimise security throughout the year.

Our own Managed Security Service (MSS) enables our clients to run continuous 24/7 vulnerability scans, supported by regular penetration tests that are focused on any areas of concern that are identified by our scanning tool.

A full penetration test or MSS solution may sound like an expensive option but it is wise to consider the investment in the context of a breach. The damage caused by even a relatively minor breach (both financially and reputationally) can far outweigh the cost of a rigorous testing schedule.

To find out more about SRM’s testing services, why not get in touch today.