GuideCommon Mistakes

Don't Confuse Vulnerability Scanning With Penetration Testing

A common mistake that creates false confidence — and how to use both tools effectively for ISO 27001.

Updated 10 Mar 2026

The Mistake

Many organisations run automated vulnerability scans and believe they've done penetration testing. These are fundamentally different activities, and auditors know the difference.

Vulnerability Scanning

What It Is

Automated tools scanning systems for known vulnerabilities against a database of signatures.

What It Does Well

Identifies missing patches
Finds known misconfigurations
Covers large numbers of systems quickly
Can run frequently (weekly or daily)
Provides baseline security hygiene metrics

What It Doesn't Do

Exploit vulnerabilities to confirm real risk
Find business logic flaws
Test authentication and authorisation properly
Chain vulnerabilities together
Think creatively like an attacker

Penetration Testing

What It Is

Skilled testers actively attempting to exploit vulnerabilities, simulating real attack scenarios.

What It Does Well

Validates whether vulnerabilities are actually exploitable
Finds complex attack chains
Tests business logic and access controls
Provides realistic risk assessment
Identifies issues scanners miss entirely

Limitations

Point-in-time assessment
Coverage depends on scope and tester skill
More expensive and time-consuming
Can't run as frequently

What ISO 27001 Expects

The standard doesn't mandate penetration testing specifically, but:

A.8.8 — Management of technical vulnerabilities
A.8.34 — Protection of information systems during audit testing

You need a vulnerability management programme. Most auditors expect to see both scanning and periodic penetration testing as part of a mature programme.

A Practical Approach

Vulnerability scanning Weekly automated scans of all systems, with defined SLAs for remediation based on severity
Penetration testing Annual external test at minimum; more frequently for critical internet-facing systems
Remediation tracking Log findings, assign owners, track resolution, verify fixes

Pro Tip

When presenting to auditors, be clear about which type of assessment you've done. Calling a vulnerability scan a "pentest" undermines credibility.

Related Modules

Standard Controls
Risk Register

Related Controls / Clauses

A.8.8
A.8.34
A.8.9

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.