What is the difference between vulnerability scanning and professional penetration testing?
My boss thinks that running an automated Nessus scan every month is the same as a penetration test. I keep trying to explain that one is just a tool and the other is a skilled human attempt to breach our systems. How can I justify the much higher cost of a third-party 'Red Team' exercise to our board?
2024-01-05 in Cyber Security by Brian Collins
| 15686 Views
All answers to this question.
The best way to explain it to the board is through the lens of 'Context.' An automated scanner finds the 'unlocked door' (the vulnerability), but it doesn't tell you if that door leads to the server room or a broom closet. A penetration tester will take that unlocked door, pivot through the network, escalate their privileges, and show exactly how they could steal the company's 'crown jewels.' Use a recent real-world example of a breach that occurred because of a chain of minor issues that a scanner would have marked as 'Low,' but a human tester was able to combine into a 'Critical' exploit.
Answered 2024-02-20 by Patricia Moore
Would you recommend a 'White Box' or 'Black Box' test for a first-time engagement? Which one gives the board more realistic results?
Answered 2024-02-23 by Thomas Baker
-
Thomas, for a first-time test, go with 'Grey Box.' It gives the testers some basic info so they don't waste half their billable hours doing basic reconnaissance. It provides the most 'bang for your buck' by allowing them to focus on finding deep logical flaws in your specific business applications rather than just testing your external firewall.
Commented 2024-02-26 by Richard Wilson
I always say: Scanners find bugs; Pen Testers find paths. One is a list of problems, the other is a story of how you get hacked.
Answered 2024-03-02 by Laura Nelson
-
That’s a perfect analogy, Laura. Using that simple phrasing often helps non-technical executives understand the value proposition of a manual test instantly.
Commented 2024-03-05 by Brian Collins
Write a Comment
Your email address will not be published. Required fields are marked (*)

