Can you test our security?
I hear that question all the time. It's a logical question, but he doesn't say much about the research that's needed. Do you want to know if an attacker can get in through a concrete technical route? Do you want to find vulnerable software and configurations? Or do you want to know if the organisation as a whole has sufficient control over digital risks?
That's three different questions. A penetration test, vulnerability scan and cybersecurity audit can all be valuable, but they give a different kind of security.
My first question is therefore not usually what research someone wants to buy. I want to know What uncertainty you want to remove.
The difference at a glance
| Research | Central question | Typical focus | Main outcome |
|---|---|---|---|
| Vulnerability scan | What known technical vulnerabilities are visible? | Systems, software, network, configurations | List of technical vulnerabilities and priorities |
| Penetration test | Can an attacker actually abuse vulnerabilities? | Attack paths, abuse, access, impact | Proven assault capabilities and technical findings |
| Cybersecurity assessment | What's the status of a specific part of our security? | Demarcated environment or theme | Deepening image with findings and points of improvement |
| Cyber Security Audit | Does the scope examined satisfy or function satisfactorily according to the pre-defined criteria? | Technique, processes, governance, suppliers, criteria and evidence | Independent audit conclusion, findings and improvement priorities |
None of these studies is automatically better . The value depends on the question you try to answer.
When do you opt for a vulnerability scan?
A vulnerability scan automatically searches for known weaknesses in systems, software and configurations.
This could include:
- outdated software versions;
- known CVE vulnerabilities;
- open network services;
- unsafe protocols;
- weak configurations;
- missing security updates;
- Internet access systems that require extra attention.
A scan is especially useful when you broad and repeatable technical visibility want to keep.
I therefore see a vulnerability scan as a tool in structural technical management. The power is repeating. Today everything can be updated and next month a new vulnerability will appear that calls for attention again.
Which doesn't tell a vulnerability scan
A scan doesn't see everything.
For example, he does not automatically tell:
- whether a vulnerability in your situation is truly abuseable;
- which business processes are affected;
- whether management rights are well-equipped;
- whether suppliers comply with their agreements;
- or incident procedures are working;
- whether back-ups can be effectively restored;
- whether management is given sufficient information to steer risks.
A long list of technical findings is therefore not yet a complete cybersecurity image.
When do you choose a penetration test?
In a penetration test, a specialist within an agreed scope actually tries to exploit weaknesses.
Where a scanner says,
“There seems to be a vulnerability here.”
a pen tester goes one step further:
“Can I use this vulnerability to gain access, escalate privileges or move further into the network?”
That makes a pen test valuable when you want to be sure about concrete technical attack paths.
Think of, for example:
- a web application that will be live soon;
- an Internet-accessible environment;
- a significant change in infrastructure;
- a new customer portal;
- a critical coupling;
- an environment where previous vulnerabilities have been identified.
A pen test provides deep insight within a limited scope
The latter is important.
A good pen test can go very deep, but does so within the agreed environment. When testing only a web application, the outcome says little about for example:
- access management in Microsoft 365;
- the quality of backups;
- incident response;
- supplier management;
- security governance;
- awareness;
- internal control.
I explain it to board members like this: can demonstrate whether a particular window can be opened. An audit also examines who is responsible for the building, which doors are controlled, whether the alarm works and what happens when someone comes in anyway.
When do you opt for a cybersecurity assessment?
An assessment deepens a defined technical, organisational or combined security issue.
You use it when you have a to assess the security issue in depth.
Examples include:
- the establishment of Microsoft 365;
- identity and access management;
- Endpoint security;
- network architecture;
- logging and monitoring;
- backup and recovery;
- Cloud configuration;
- technical services by an external IT partner.
An assessment may review document research, interviews, documents, configurations and technical information and perform targeted checks.
When demand is primarily technical, we will set up the research as IT Security Assessment within the Cybersecurity Assessment.
The main difference with a scan or pen test is that the research demand can be wider than just . . are abused?
When do you choose a Cyber Security Audit?
A Cyber Security Audit is appropriate when you need an independent, systematic review of predefined criteria and an audit conclusion.
Examples include:
- Do we have any demonstrable control over our main cyber risks?
- Are security measures effective in practice?
- Can the board and executive management rely on the information they receive?
- Is our IT service provider detectable in control?
- Are responsibilities between organisation and suppliers clear?
- Can we fix it when a critical environment fails?
- Are measures only described or actually implemented?
Then I look at technology and the organisation around it.
This may include topics such as:
- Governance;
- risk analysis;
- identity management;
- endpoints;
- network;
- Vulnerability management;
- logging;
- monitoring;
- backup;
- recovery;
- incident response;
- suppliers;
- awareness;
- policy;
- internal control;
- Management report.
The audit shall establish the review criteria in advance, use traceable evidence and attach the audit conclusion and findings to risk, impact and priority.
For a board member, that difference is important. A technical finding will only be controlled when it is clear that the what it means for continuity, responsibility and decision-making.
“We had a penetration test, so are we secure?”
I wouldn't draw that conclusion.
A good pen test can give a lot of certainty about the assault plane tested. It's just not a ruling on the entire organisation.
I also encounter organisations that are technically quite mature, while responsibilities, suppliers' agreements or incident preparation have hardly been developed. I see organisations with excellent policies, the other way around, while in the technical environment simple vulnerabilities remain.
Cybersecurity works precisely at the intersection of technology, people, processes and governance.
Therefore, the investigation must be consistent with the risk you want to control.
Can you combine research?
Yes. Often a combination delivers the best image.
Example 1: Technical level audit
An organisation wants to know if the information security is in a demonstrable state of order.
The audit shall review the agreed scope against predefined criteria. During the research there is doubt about the technical security of an internet environment.
Then a targeted vulnerability scan or pen test can provide additional assurance.
Example 2: first assessment, then pen test
An organisation has set up a new cloud environment.
An assessment first assesses architecture, settings, accounts and management. Afterwards a pen test is performed on the externally accessible part.
The two studies answer different questions and reinforce each other.
Example 3: scan as structural control
An organisation has set up the basic security.
Periodic vulnerability scans then become part of the normal management cycle, while annual or major changes lead to broader assessment.
What question would I ask as a board member?
As CEO, CFO, CIO or COO you don't usually have to decide which scanner or pen test method is needed.
You could really get the research question sharp.
I would at least ask these questions:
- What do we want to know about?
- Which critical processes or systems can be affected?
- Do we want to find technical vulnerabilities or also assess the functioning of our control?
- Do we need independent evidence?
- What decisions do we want to make after the investigation?
- Who will own the follow-up?
If these questions are clear, the choice of research will usually be much simpler.
What about the IT manager?
For an IT manager, the emphasis is often something else.
I'd look at that:
- Scope;
- technical depth;
- necessary access;
- production impact;
- test windows;
- responsibilities of suppliers;
- reporting format;
- reproducibility of findings;
- prioritisation;
- test;
- connection to existing vulnerability and change management.
A report is of little value when the findings disappear in a folder after delivery.
So, please make a pre-arrangement how findings are monitored and when a point is detectable.
What form does your question fit?
Use as a rule of thumb:
You want to find widely known technical weaknesses?
Choose a vulnerability scan.
Do you want to know if an attacker can penetrate or abuse a concrete environment?
Pick a penetration test.
Do you want to have a specific technical or organisational environment assessed in depth?
Choose a cybersecurity assessment.
Do you want to have independent testing of whether the scope examined is demonstrably satisfactory or operates according to pre-defined criteria?
Choose a Cyber Security Audit.
Do you doubt between baseline assessment, assessment and audit? For this reason, We have a separate choice help.
My starting point: start with uncertainty
I'm not in favour of investigating the investigation.
A pen test because we do a pen test every year can be fine, as long as it is clear what risk is covered. The same applies to audits, scans and assessments.
So start with the uncertainty you want to remove. Then determine the evidence needed to make a decision.
This usually results in a better scope, a more useful report and more results than when you start with the name of the research.
Want to know more about an audit?
Read Also What is being investigated in an IT security audit?
Do you want to have an independent assessment of how technical and organisational security measures work in practice? Then look at the Cyber Security Audit of Kynexis.


