Where a penetration test goes deep on a defined scope, a vulnerability assessment goes broad: internal and external networks, infrastructure and applications, scanned and triaged so you get a prioritised list of what actually needs fixing first, not a raw export of everything a tool flagged.
Both have a place, and most mature security programmes run both on their own cadence.
Wide coverage across your networks, infrastructure and applications. Fast, triaged, and built to run more frequently than a full test.
Narrower scope, manual and adversarial, chaining weaknesses together to prove real business impact. See our penetration testing service.
An automated scan alone will happily report hundreds of findings, many of them irrelevant to how you actually operate. The analyst triage is what turns that into a list worth working through.
Everything reachable from the internet, scanned for known vulnerabilities and misconfiguration.
What is visible and exploitable from inside your network, including legacy systems and default configurations.
Servers, endpoints and network devices assessed against known vulnerability databases.
Web applications and APIs scanned for common weaknesses ahead of, or alongside, a full application penetration test.
Agree which networks, infrastructure and applications are in scope, and the assessment window.
Automated scanning across the full scope, with an analyst removing false positives and adding context.
Findings rated Critical, High, Medium or Low, ordered by real-world risk with specific remediation guidance.
Once remediated, we retest to confirm the fix holds before a finding is considered closed.
A vulnerability assessment covers breadth: scanning across a large estate, triaged by an analyst, to identify and prioritise known weaknesses. A penetration test covers depth: manual, adversarial testing that chains weaknesses together to prove real business impact on a narrower scope.
No. Automated scanning is the starting point, but every result is triaged by an analyst who removes false positives and adds context, so what you receive is a prioritised list, not a raw tool export.
Yes. Once you have remediated, we retest to confirm the fix holds before we consider a finding closed.
Internal and external networks, infrastructure and applications. Scope is agreed with you up front based on what you are trying to protect.
Tell us what you're trying to protect, and we'll scope an assessment that gives you a prioritised, actionable list rather than a wall of raw findings.
Confidential, no obligation, and scoped around your estate.