"We need a pentest." We hear this often. Roughly half the time it is the right answer. The other half, the customer needs something different — cheaper, or considerably broader.
The confusion is understandable. Three distinct services are sold under similar names, vendors define the terms however they like, and the price range is wide enough that cost tells you nothing. A quote for €1,200 and a quote for €16,000 can carry the same label.
This article breaks down what each service is, what question it answers, and how to tell which one you actually need.
Quick comparison
Vulnerability scan | Penetration test | Security assessment | |
|---|---|---|---|
Question | Where are our known holes? | Can it be exploited? | Is the organisation in good shape? |
Who does it | A tool, minimal human input | A tester, heavy human input | A consultant, interviews and analysis |
Scope | Technical, specific systems | Technical, defined target | Technology, process, people, governance |
Duration | Hours to days | 1–4 weeks | 2–8 weeks |
Output | List of findings | Report with attack path | Maturity report and remediation plan |
Cost (CZ market) | CZK 20–80k | CZK 80–400k | CZK 150–600k |
Frequency | Continuous, ideally automated | Annually or after major changes | Every 1–2 years |
Treat the figures as indicative. Scope decides the price, not the label.
Vulnerability scan
Answers: Which known vulnerabilities exist in our environment?
A scan is an automated check. The tool walks through the given addresses or systems, compares software versions and configurations against a database of known vulnerabilities, and produces a list of findings with severity scores.
What it does well. It finds outdated software, known flaws with assigned CVEs, missing patches, weak cipher suites, and default configurations. It covers a large scope quickly and cheaply, and it can be run repeatedly, ideally on a schedule.
What it cannot do. It will not spot application logic flaws. It has no idea that an ordinary user can reach another customer's data through three steps. It does not chain minor findings into a realistic attack. And it produces false positives — in larger environments, the proportion of findings that are not real problems is substantial.
When you want it. Continuously. Vulnerability scanning should not be a project but a running process. If you do not currently know how many unpatched systems you have, this is your first step — not a pentest.
Penetration test
Answers: Can this actually be exploited, and how far does an attacker get?
A pentest is a controlled attack. The tester attempts to break in using the same techniques as a real attacker, with the difference that there is a contract, a defined scope, and no intent to cause damage.
The distinction from a scan is chaining. A finding a scanner rates as low severity may, combined with two others, be the path to administrative privileges. Automation does not see that.
Main variants:
External pentest — the outside view, covering what is reachable from the internet. The most common and cheapest option.
Internal pentest — simulates an attacker already inside the network. It answers what happens when someone clicks a phishing link. In practice this variant tends to produce the most findings.
Web or mobile application test — focused on a specific application, usually following OWASP methodology.
Red team — a long-running simulation of a real adversary including social engineering and physical access, without warning the defensive teams. This only makes sense for organisations that already have working detection, because detection is precisely what it tests.
When you want it. When the basics are in place and you want to know whether they hold. Before releasing a new application, or after a significant architecture change. When a customer, a regulator, or an insurer requires it.
When it is wasted money. When you already know you have unpatched systems and no multi-factor authentication. The pentest will confirm it and you will have paid for information you already had. Fix what you know about first, then test.
Security assessment
Answers: Is the organisation in good shape, and where are the biggest risks?
An assessment is not a technical test. It is an evaluation of the overall security posture — architecture, processes, governance, people, suppliers, and incident readiness.
Where a pentest says "this application has this flaw," an assessment says "you have no leaver process, nobody has reviewed access rights in three years, and backups are never tested."
What it typically covers. Interviews with key people, review of documentation and policies, architecture assessment, configuration review of major systems, comparison against a standard (ISO 27001, NIST CSF, CIS Controls) or a regulation (NIS2, DORA), and a remediation plan sequenced by risk.
When you want it. When you do not know where you stand. When you fall under regulation and need to understand the gap to compliance. When new leadership or a new security manager arrives. When a company needs to get its bearings after an acquisition or rapid growth.
How to spot a bad one. You receive a hundred-page document of generic recommendations that would fit any other company after a find-and-replace. A good assessment contains specifics from your environment and a plan with sequencing and effort estimates.
Which one to choose
A simple decision path.
You do not know what you have and nobody owns security. → Security assessment. Testing details is pointless without an overview.
You have an overview but do not know if you are patched. → Vulnerability scanning, repeatedly.
You have the basics and want to verify they hold. → Pentest.
You are releasing a new application. → Application pentest before launch.
A customer wants evidence of your security. → Depends on what exactly they want. Sometimes a questionnaire answered from an assessment suffices; sometimes they require a pentest report. Ask them.
You fall under NIS2 or DORA. → A compliance-focused assessment first, then a pentest as one of the resulting controls.
What to ask a vendor
A few questions that reveal more than the price.
Who will actually do the work and what is their experience? At larger firms a senior sells and a junior tests. Ask for the names and certifications of the people on the project.
What does a sample report look like? Request an anonymised example. You will see whether the output is usable or just a tool export.
How much time is allocated to manual work? For a pentest this is the decisive question. If the vendor cannot answer it, they are likely delivering a scan under a different name.
Is a retest included? After fixing findings you should be able to verify they are genuinely resolved. Some vendors include this; others charge separately.
What happens if you find something critical mid-test? "We'll put it in the report" is the wrong answer. Immediate notification is the right one.
Three most common mistakes
Buying a pentest instead of an assessment. The company does not know where it stands but orders a technical test of one system. It gets ten findings on a single application while nobody addresses the missing backups and unmanaged access rights.
Treating a scan as a pentest. Some vendors sell automated scanning under the penetration test label. You can spot it by the price, the duration, and the absence of any narrative in the report describing how the tester got somewhere.
Letting findings sit. The most expensive test is the one after which nothing happens. A report does not improve security by itself. Before ordering, agree who will drive remediation and by when.
Summary
A scan finds known holes, automatically and continuously. A pentest verifies whether they can be exploited and how far an attacker gets. An assessment answers whether the organisation as a whole is in good shape.
When in doubt, start with the broadest question. Establishing where you stand is always cheaper than testing the details of a system that may not be your riskiest one.
What we do about it
We advise on what you need. Before selling anything, we talk through the situation. If a cheaper option or an entirely different service fits better, we say so.
We deliver it. Maturity assessment against NIST CSF, ISO 27001, or CIS Controls, architecture review, penetration testing, and compliance readiness checks for NIS2 and DORA. → Security Assessment
We drive the remediation. This is where most organisations stall. Producing findings is easy; closing them is not. We can take ownership and see it through. → vCISO and Security Leadership
We test the people too. A pentest will not tell you how many employees click a phishing link. A simulation will. → Phishing simulation
Large firms will send you a two-hundred-page report. We go through every line with you and stay until it is actually resolved.
The initial consultation is free and comes with no obligation. We respond within 24 hours.