What is penetration testing, and how is it different from a vulnerability scan?
A vulnerability scan is automated and tells you what might be exploitable; a penetration test is human-led and demonstrates what actually is, by exploiting it. They cost, take and tell you completely different things, and buying one while expecting the other is a common and expensive mistake.
Vulnerability scanning. Automated tools check systems against databases of known issues — missing patches, outdated versions, weak configurations, exposed services. Fast, cheap, repeatable, and appropriate to run continuously.
Its limits: it produces false positives requiring triage, cannot chain several minor issues into a serious one, cannot exploit business logic flaws, and has no judgement about what matters in your context.
Penetration testing. A skilled tester attempts to compromise systems as an attacker would — combining findings, exploiting logic errors, escalating privileges and moving laterally. The output demonstrates realised impact: not "this version has a known flaw" but "we reached your customer database, and here is how".
The types:
Black box, with no prior information, simulating an external attacker and spending much of the budget on reconnaissance.
Grey box, with some access or documentation — usually the best value.
White box, with full access and source code, which finds the most per pound spent.
The related activities, frequently confused with it:
Red teaming, a goal-oriented exercise testing detection and response as much as defences, usually without the defenders knowing.
Bug bounty, continuous crowdsourced testing paid per finding.
Code review and threat modelling, which find things testing cannot.
What makes a test worth having:
A clear scope and defined objectives, since a test of everything is a test of nothing.
Qualified testers with recognised certification, and a written authorisation — testing without explicit permission is a criminal offence.
A retest included, verifying fixes.
Findings prioritised by business impact, not by generic severity score.
Acting on the report, which is where most value is lost — an unremediated test is an expensive document.