A vulnerability scan is an automated check that lists known weaknesses across your systems, and it should run regularly. A penetration test is carried out by a person who confirms which weaknesses are real and shows how they could be combined to cause harm, usually once a year. Most businesses need both.
What is the difference?
| Vulnerability scan | Penetration test | |
|---|---|---|
| Who does it | Automated tool | Skilled tester, using tools |
| Depth | Broad, finds known issues | Deep, exploits and chains issues |
| False positives | Common without review | Findings are confirmed |
| How often | Monthly or continuous | Annually and after major change |
| Output | List of weaknesses and severity | Proven attack paths and business impact |
| Best for | Staying on top of new weaknesses | Independent proof your defences hold |
When do you need a vulnerability scan?
All the time. New weaknesses are published constantly, and most attacks use ones that already have a fix available. Regular scanning, with someone reviewing the results and tracking fixes, is the routine hygiene that keeps your exposure low between tests.
When do you need a penetration test?
- Before launching a new website, app or platform.
- When a client, insurer or tender asks for one.
- After major changes to your network or cloud setup.
- At least once a year, as independent evidence that controls work.
Frequently asked questions
No. A scan cannot confirm whether a weakness is exploitable or show how several small issues combine into a serious one. That takes a person.
A penetration test is a structured form of ethical hacking: an authorised, scoped attack with agreed rules and a written report.
Regular vulnerability scanning is the cheaper ongoing control. Add a penetration test when you launch something important, or when a client or contract requires one.