# Vulnerability scan vs penetration test.

> A vulnerability scan is automated and broad; a penetration test is manual and deep. How they differ, what each costs in effort, and which you need.

Canonical: https://cybersecuritylondon.com/vulnerability-scan-vs-penetration-test


By Cyber Security London, published 8 October 2026.

**In short:** A vulnerability scan is an automated check that lists known weaknesses across your systems, and it should run regularly. A penetration test is carried out by a person who confirms which weaknesses are real and shows how they could be combined to cause harm, usually once a year. Most businesses need both.

## What is the difference?

|  | Vulnerability scan | Penetration test |
| --- | --- | --- |
| Who does it | Automated tool | Skilled tester, using tools |
| Depth | Broad, finds known issues | Deep, exploits and chains issues |
| False positives | Common without review | Findings are confirmed |
| How often | Monthly or continuous | Annually and after major change |
| Output | List of weaknesses and severity | Proven attack paths and business impact |
| Best for | Staying on top of new weaknesses | Independent proof your defences hold |

## When do you need a vulnerability scan?

All the time. New weaknesses are published constantly, and most attacks use ones that already have a fix available. Regular scanning, with someone reviewing the results and tracking fixes, is the routine hygiene that keeps your exposure low between tests.

## When do you need a penetration test?

- Before launching a new website, app or platform.
- When a client, insurer or tender asks for one.
- After major changes to your network or cloud setup.
- At least once a year, as independent evidence that controls work.

## Frequently asked questions

### Can a vulnerability scan replace a penetration test?

No. A scan cannot confirm whether a weakness is exploitable or show how several small issues combine into a serious one. That takes a person.

### Is a penetration test the same as ethical hacking?

A penetration test is a structured form of ethical hacking: an authorised, scoped attack with agreed rules and a written report.

### Which should a small business start with?

Regular vulnerability scanning is the cheaper ongoing control. Add a penetration test when you launch something important, or when a client or contract requires one.

## Sources

- [Cyber Security Breaches Survey 2025, Department for Science, Innovation and Technology](https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025)

## How we can help

- [Vulnerability Management](https://cybersecuritylondon.com/vulnerability-management)
- [Penetration Testing](https://cybersecuritylondon.com/penetration-testing)

## Contact

Email enquiry@cybersecuritylondon.com or use the enquiry form at https://cybersecuritylondon.com/#contact. Cyber Security London, The Leather Market, London Bridge, London.
