Penetration Test vs Vulnerability Scan

One is hygiene, the other is proof. Plenty of invoices confuse the two. Here's how not to.

Last updated

What's the difference between a penetration test and a vulnerability scan?

A vulnerability scan is an automated tool matching your systems against a database of known issues. Fast, cheap, shallow, and noisy with false positives. A penetration test is a skilled human actively attacking your systems: chaining weaknesses, abusing business logic and proving real-world impact. Scans tell you what a tool can see; a pentest tells you what an attacker can do.

How do they compare side by side?

Dimension Vulnerability scan Penetration test
Performed by Software A senior human tester (with tooling for breadth)
Finds Known vulnerability classes with signatures Business logic flaws, chained attacks, authorisation failures
False positives Common. Someone must triage the output Rare. Every finding is validated and reproduced
Proves impact No. Flags possibilities Yes. Demonstrates what an attacker achieves
Cost Low. Tooling from free to a few hundred dollars monthly AU$6,000–18,000+ depending on scope, fixed-fee
Cadence Continuous or monthly Annually and after major changes
Satisfies auditors & enterprise customers Rarely on its own Yes. The expected evidence for ISO 27001, SOC 2 and security reviews

When should you choose which?

This one isn't either/or. Mature teams run both, on different clocks.

Use vulnerability scanning when…

  • You want continuous coverage of known issues across a large estate. Patch drift, misconfigurations, expired certificates.
  • You need cheap, frequent hygiene between deeper engagements.
  • You're feeding a patching programme, not answering "are we actually exploitable?"

Use a penetration test when…

  • An auditor, certification or enterprise customer requires evidence of testing. ISO 27001, SOC 2, PCI DSS, security questionnaires.
  • You're launching or materially changing an application, API or AI feature.
  • You want to know what a real attacker could do with your business logic, not what a database of CVEs says about your versions.

How does Ironbark Cyber fit?

Ironbark Cyber does the human half of this comparison: manual, scope-tailored penetration testing across web applications, APIs, networks, cloud and LLM applications. Senior-only, fixed-fee, with critical findings escalated the day we find them and a free 90-day retest of fixes. We use scanners the way a builder uses a spirit level: for breadth, never as the deliverable. The honest recommendation: keep (or start) scanning continuously. It's cheap and useful. And bring in a pentest when you need to know what's actually exploitable, or when someone with a clipboard needs proof.

FAQ

Frequently asked questions

Is a vulnerability scan good enough for compliance?

Sometimes on paper, rarely in substance. ISO 27001, SOC 2 and most enterprise customer reviews expect penetration testing, not scanning. And auditors increasingly know the difference. If a report you paid for reads like scanner output with a logo on it, you bought a scan.

How much does each cost?

Scans are cheap or free: open-source tools, or commercial platforms from a few hundred dollars a month. Penetration tests are senior human time: Ironbark Cyber's published ranges are AU$8,000–18,000 for a web application, AU$8,000–15,000 for an API and AU$6,000–12,000 for an external network, fixed-fee.

How often should we do each?

Scan continuously or at least monthly. It's automated hygiene, so there's no reason not to. Penetration test at least annually, plus after major changes: a new product, a re-architecture, an acquisition, or a significant new AI feature.

Can a scanner find business logic flaws?

No. Scanners match patterns of known vulnerability classes. Business logic abuse. Paying $0 for a $500 order, accessing another tenant's records, skipping an approval step. Has no signature to match. These are the findings that lead to breaches, and they are found by humans.

We already run a scanner. Will a pentest just repeat what it says?

A good one won't. Ironbark Cyber testers use tooling for breadth and then spend the engagement where scanners can't go: authentication and authorisation logic, chained findings, business logic. If a pentest quote is suspiciously cheap, ask who is doing the work and how much of it is a scanner.

Contact

Talk to us

Tell us what you're trying to protect, secure or build. We'll come back with a plan.

Prefer to talk live? Book a call →

By submitting this form, you agree to our privacy policy.