Choose the appropriate depth

Vulnerability scan versus penetration test: what is the difference?

A tool-assisted vulnerability scan finds signals at scale. A reviewed assessment validates and prioritises selected evidence. A penetration test goes deeper into human-led attack paths. The right choice depends on the risk and decision involved.

Side-by-side

Three services that answer different questions.

“Security scan” is often used loosely. Before comparing prices, compare how findings are validated, how much human testing is included and whether the result is suitable for the business risk involved.

A security specialist comparing broad vulnerability scanning with focused manual testing
Match depth to exposureAssessment depth should reflect the attack surface, business risk and decision the result must support.
QuestionTool-assisted vulnerability scanLetsSecure reviewed assessmentFormal penetration test
Primary purposeIdentify known indicators and configuration issues quickly.Turn focused testing and reviewed evidence into a small-business action plan.Explore complex attack paths and demonstrate impact in greater depth.
Human involvementUsually limited to setup and export.Relevant findings and evidence are reviewed before reporting.Substantial analyst-led testing, validation and reporting.
Typical depthBroad but tool-dependent.Scoped black-box website and authorised journey assessment.Deeper manual coverage defined by a detailed rules-of-engagement document.
Best fitRoutine monitoring and early indicators.Small businesses needing practical priorities and developer guidance.High-risk, regulated, complex or assurance-sensitive systems.
LimitCan produce noise or miss business logic.Not a complete penetration test or guarantee that every vulnerability is found.Still a point-in-time assessment bounded by time and scope.

LetsSecure methodology

More interpretation than a tool export; less depth than a penetration test.

The $159 initial audit deliberately sits between raw tool output and a formal penetration test. It is designed to help a small business decide what to fix next without misrepresenting the level of assurance.

  1. 01 / ScopeConfirm permitted websites, logged-in areas and exclusions.
  2. 02 / MapIdentify the authorised attack surface and relevant technologies.
  3. 03 / CheckPerform controlled focused testing and gather evidence.
  4. 04 / ReviewRemove unsupported noise and rank practical remediation work.
Scope and method excerpt from the LetsSecure example web application security report
The comparison example states how the assessment was run and where its boundary differs from a formal penetration test.

Evidence matters

The report should reveal the level of confidence.

A useful assessment separates observed behaviour, plausible impact, confirmed findings and areas that were not tested. It should never turn a scanner label into a certainty without review.

See the reporting standard

Why the distinction matters

A visible admin path is not automatically a vulnerability.

A security tool may flag the path. A reviewed assessment considers whether it is expected, what protections are present and whether a specific fix is justified. A penetration test may go further by exploring role boundaries, chained weaknesses and demonstrated business impact.

Choose a reviewed assessment when

  • You need a practical first assessment
  • The system is a standard small-business website or web application
  • You want a developer-ready list before commissioning deeper work
  • A point-in-time review meets the decision need

Choose a formal penetration test when

  • The system is high-risk, regulated or operationally critical
  • Contracts or compliance requirements specify one
  • Complex business logic or multiple privilege levels need deeper testing
  • You need broader manual exploitation or assurance

LetsSecure starting point

Reviewed website assessment from $159.

The service provides practical evidence and priorities but does not call itself a penetration test. High-risk or regulated systems should engage a suitably qualified penetration-testing provider.

Need the practical first step?

Book a reviewed website audit.

LetsSecure confirms the scope before testing begins.

Book Audit