By J. Mesa
A customer contract, an insurance form, or an auditor asks whether you have had a penetration test. A vendor quotes you $900. Another quotes $14,000. Both call the service a pen test. One of them is selling you a vulnerability scan with a nicer cover page. Knowing the difference saves you money and keeps you out of trouble with the auditor.
What is a vulnerability scan?
A vulnerability scan is an automated check that compares your systems against a database of known weaknesses. A scanning tool such as Nessus, Qualys, or OpenVAS probes your computers, servers, firewalls, and websites. It reports missing patches, outdated software, weak settings, and default passwords, and it ranks each finding by severity.
A scan runs in minutes or hours. It covers a lot of ground. It also produces false alarms, and it cannot tell you which findings matter most to your business.
What is a vulnerability assessment?
A vulnerability assessment adds a person to the scan. An analyst runs the tools, removes the false alarms, checks the findings against how your business operates, and gives you a prioritized list with steps to fix each item.
The question it answers: what weaknesses do we have, and which ones should we fix first?
What is a penetration test?
A penetration test is an authorized, simulated attack. A skilled tester tries to break in the way a criminal would, with your written permission and inside agreed limits. The tester finds weaknesses, exploits them, chains small problems into large ones, and documents how far the attack reached.
The question it answers: what can an attacker do to us, and what would it cost us?
A scan might report a missing patch on a file server and a weak password policy as two medium findings. A penetration tester uses the weak password to log in as a receptionist, uses the missing patch to become an administrator, and shows you a screenshot of your payroll folder. Same weaknesses. Different level of proof.
What is the difference between a vulnerability assessment and a penetration test?
- Goal. An assessment finds as many weaknesses as possible. A penetration test proves what an attacker can achieve.
- Method. An assessment relies on automated tools with human review. A penetration test relies on human skill supported by tools.
- Breadth and depth. An assessment goes wide. A penetration test goes deep on a defined scope.
- Time. An assessment takes a day or a few days. A penetration test takes one to three weeks.
- Frequency. Run assessments each quarter or each month. Run penetration tests once a year and after major changes.
- Output. An assessment delivers a ranked list of findings. A penetration test delivers a narrative of the attack, evidence, business impact, and fixes.
- Cost. A penetration test costs several times more.
Which one does my small business need?
Start with vulnerability assessments. If you have never scanned your network, a penetration tester will spend your money finding problems a scanner would have found for a fraction of the price.
Follow this order:
- Run a vulnerability assessment.
- Fix the critical and high findings.
- Scan again to confirm the fixes.
- Repeat each quarter.
- Add a penetration test once the basics hold, or when a rule or a contract requires one.
Buy a penetration test sooner if you take card payments on your own systems, fall under the FTC Safeguards Rule, sell software or services to larger companies that demand one, or run a custom web application that holds customer data.
How much does each one cost?
Prices vary by size and scope. Typical ranges for a small business:
- External vulnerability scan: $100 to $500 per scan, or a low monthly subscription
- Vulnerability assessment with analyst review: $1,500 to $5,000
- Penetration test of a small network or one web application: $5,000 to $20,000
- Larger or more complex environments: $20,000 and up
A “penetration test” quoted under $2,000 with a two-day turnaround is almost certainly an automated scan. Ask the vendor what the tester does by hand.
What types of penetration tests exist?
- External network. Attacks your internet-facing systems from outside.
- Internal network. Starts from inside the office, as if an attacker already compromised one computer or one employee.
- Web application. Targets a website, portal, or API for flaws such as broken access controls and injection.
- Wireless. Tests the Wi-Fi networks and guest separation.
- Social engineering. Tests the people with phishing emails, phone calls, or an attempt to walk into the building. See our post on how hackers get in.
- Physical. Tests doors, badges, and server room access.
Testers also describe how much they know going in. In a black box test, the tester starts with no inside information. In a gray box test, the tester gets a user account or network diagram. In a white box test, the tester gets full documentation. Gray box gives most small businesses the best value, because the tester spends your budget attacking and wastes none of it guessing.
What do compliance rules require?
- PCI DSS requires external vulnerability scans each quarter by an Approved Scanning Vendor, internal scans each quarter, and penetration tests each year for merchants with larger or more complex card environments.
- The FTC Safeguards Rule requires covered financial businesses to run annual penetration tests and vulnerability assessments every six months, unless they use continuous monitoring. Businesses holding data on fewer than 5,000 consumers are exempt from this part.
- HIPAA requires a risk analysis and periodic technical evaluation. It does not name penetration testing, but scans and tests are the standard way to meet the requirement.
- Cyber insurers and enterprise customers ask for recent reports in applications and vendor questionnaires.
How do I choose a penetration testing vendor?
Ask these questions before you sign.
- Who performs the test, and what certifications and experience do they hold? Look for OSCP, GPEN, or similar hands-on credentials.
- What methodology do you follow? Good answers reference NIST SP 800-115, PTES, or the OWASP Testing Guide.
- How much of the work is manual?
- Can I see a sample report with the client details removed?
- Do you carry professional liability insurance?
- Is a retest of fixed findings included in the price?
- How do you handle and delete the data you collect?
What should a good report include?
- An executive summary a business owner can read in five minutes
- The scope, dates, and methods
- Each finding with a severity rating, evidence, and the steps to reproduce it
- The business impact in plain language
- Specific instructions to fix each finding
- For a penetration test, the attack path from first foothold to final objective
How do I prepare for a test?
- Define the scope in writing: which systems, which addresses, which hours.
- Sign a rules of engagement document and an authorization letter. Testing without written permission is a crime.
- Notify your IT provider, your hosting company, and your cloud vendors as their policies require.
- Confirm your backups work before testing begins.
- Name one contact on each side for emergencies.
- Decide in advance who receives the report. It is a map of your weaknesses, so treat it as confidential.
What happens after the test?
The report has no value until you act on it. Assign each finding an owner and a due date. Fix the critical items first. Schedule the retest. Feed the lessons into your policies and your staff training, because many findings trace back to a habit and not to a machine.
Your next step
If you have never run a scan, start there. Cerberus Cybersecurity performs risk and compliance assessments for small businesses and measures the results against PCI DSS, HIPAA, and GLBA. Contact us to scope an assessment that fits your size and your budget.