What is the difference between a penetration test, also called a pentest, and a vulnerability assessment? In this blog, we explain it in detail and indicate which scenario is the best choice for your organisation. Whichever you choose, both approaches help your organisation stay one step ahead of hackers!
What are vulnerability assessments?
In a vulnerability assessment, we carry out various tests on specific websites, web applications, IP addresses and ranges. We use automated scanning programs, both commercial and open source. The latter are particularly popular with malicious hackers and therefore useful for our investigation.
Broadly speaking, a vulnerability assessment follows these steps:
- Identify all connected resources in an organisation's IT system.
- Create a list of valuable assets in priority order.
- Assess all known vulnerabilities across the entire attack surface, from login screens to URL parameters and mail servers.
What is a penetration test?
In a penetration test, or pentest, we simulate a hacker's attack. Our penetration testers do this by searching the system for vulnerabilities. Once they find them, they try to exploit them and examine what a hacker could achieve: gaining system access, obtaining passwords, extracting data or encrypting it. Using public and private databases, the tester identifies which exploits apply to the vulnerability and uses them to gain entry, even if existing exploits need adapting or new ones developing to achieve the objective.
We carry out “black-box” penetration tests without prior knowledge of the network or organisation and without access to source code or similar information. This form of testing most closely resembles a malicious hacker's approach.
What can I expect from each approach?
To answer that, you should really reverse the question: what do you want to achieve with the assessment?
A vulnerability assessment provides clarity about all weaknesses in the infrastructure and network. A penetration test shows how hackers could enter your system and what damage they could then cause, often through just one vulnerability. The measures an organisation takes after either test can therefore differ considerably.
A vulnerability assessment report covering all vulnerabilities
A vulnerability assessment produces an automatically generated report of the results: a list of identified vulnerabilities ranked by severity and business risk.
In addition to this automatically generated report, we also provide a manually prepared report with a real-world risk score. This answers whether potential medium-risk vulnerabilities could combine into a high or even critical risk. There may also be mitigating factors for critical findings, or a malicious hacker or malware may need more information to exploit the system in practice.
A real-world risk score is also influenced by:
- the system or application in which the vulnerability exists
- the difficulty of exploiting the vulnerability
- mitigating factors
- dependencies between vulnerabilities and exploits
The reports give organisations guidance on resolving the vulnerabilities found. They also receive recommendations for more targeted cybersecurity measures, reducing the likelihood of damage from cyberattacks. The advice also covers how organisations can better anticipate attacks and limit their negative effects.
Penetration test reports examine the attack method used in detail
After the assessment, the penetration tester describes the attack method or exploits in a report, including exactly which data could be compromised. The report also explains what a hacker could do with that data and how it affects the business. This quickly gives directors, managers and non-technical employees, who may not fully understand the technology behind the tests, a picture of the consequences an attack could have for the business.
It is important to know that a penetration tester does not assess the vulnerabilities. After all, the sole purpose of a penetration test is to establish whether an attack is possible at all.
Which is best for my organisation?
To answer that, it is important to know how mature your organisation's cybersecurity is. What security mindset prevails among employees and within the business?
Penetration tests reveal cracks in your security architecture
Penetration tests are highly specific and therefore best suited to environments whose web and network security is very robust, or at least considered so. Organisations can ask the tester to perform a specific action, such as “Try to gain access to a database containing transaction or bank details” or “Try to modify or delete a particular record”. The aim is to use the resulting knowledge to reduce exposure to specific risks.
Penetration testers simply look for weaknesses in the architecture. While vulnerability assessment testers mainly examine vulnerabilities and misconfigurations in systems, penetration testers often also use phishing, social engineering and on-site visits to achieve their objective. They essentially do exactly what malicious hackers would do. For example, a tester may try to connect to a server unnoticed and then demonstrate that confidential data can be retrieved. This is a good way to show what attackers are capable of. A penetration tester can carry out an endless series of attacks this way.
Our advice is to commission a penetration test at least once a year.
Which scenarios can help me decide?
Vulnerability assessments and penetration tests should be carried out on web environments, network devices and internal and external servers. It is very important to establish whether an attack can be carried out from outside, for example by a malicious attacker targeting public internet-facing assets, or from inside, for example by a disgruntled employee or customer, a user with inappropriate permissions, or a malware- or ransomware-infected device on the internal network.
Vulnerability assessments help businesses meet standards
Some organisations must work to particular standards, such as ISO 27001/2, NEN 7510 or other standards and laws. The General Data Protection Regulation (GDPR) also requires organisations to take appropriate technical and organisational measures to secure personal data. Organisations wanting to know whether their current architecture, systems and devices would pass a GDPR assessment, for example, benefit greatly from a vulnerability assessment.
Penetration tests help organisations stay one step ahead of hackers
Penetration testers examine security from a different perspective. They identify security risks in the same way as hackers, by carrying out attacks with one objective: gaining access! It is best to give penetration testers a broad brief. Let them carry out attacks you have devised or that arise from their own experience.
What about the testers?
The choice between a vulnerability assessment and a penetration test also raises the question of who will carry it out. Do you choose external expertise or an in-house tester?
Cybersecurity experts ensure continuous improvement of the security posture
Vulnerability assessments are not a matter of pressing a button and letting the test run. Although partly automated, the person carrying out the assessment must be trained and highly experienced. They must know which environments and attack surfaces to examine and exactly what to investigate, since automated security scanners still require configuration. They must also be able to interpret the assessment results, assess risk correctly and know what needs to happen next.
In-house cybersecurity experts responsible for vulnerability assessments ensure their organisation's security posture improves continuously. First, they establish a baseline to measure improvement. They also help raise awareness within the organisation and continually reduce security risks. They constantly expand their knowledge and skills, and are more loyal to the organisation they work for than hired professionals.
However, too few experienced people work in cybersecurity, making it difficult and expensive to attract in-house experts. Hiring external professionals offers a solution, with the additional benefit that they operate independently within your organisation.
Penetration testers tell it as it is
Penetration testers must also be experienced professionals with specific skills.
Most professionals in this industry believe pentesters should be independent, external professionals. They need sufficient distance from your organisation, without being constrained by issues such as financial security, loyalty or politics. Only then can they tell the blunt truth about your security status, even if it hurts!
What should it cost?
The price of a vulnerability assessment depends on the scope of the assignment. For small organisations, the cost will be considerably lower than for a large enterprise with thousands of potentially vulnerable machines, IP addresses and internet hosts.
Whatever it costs, a vulnerability assessment will always deliver a higher return. However deeply a pentester explores your system, they only ever investigate one aspect in a particular direction. Vulnerability assessments go further, providing an accurate, broad picture of an enterprise's security level.
So, which do we choose? A pentest or an assessment?
Both. Both approaches can reveal security gaps and identify less obvious vulnerabilities you had never considered. One thing is certain: if you do not scan or test, you will lose data. The only question is when.
In a mature, preventive approach, vulnerability assessments and scans form part of an Information Security Management System (ISMS). You then hire ethical hackers to do what real hackers do, but without the harmful consequences. After reading all the reports and results and reviewing the recommendations, you can make an informed decision about how to maintain a high level of security within your organisation and stay one step ahead of the bad guys.
