Vulnerability scan vs. penetration test
They answer different questions, and most compliance programs need both:
- Vulnerability scanning is automated and broad. It checks every reachable system for known weaknesses and is repeated on a schedule, often monthly or quarterly. It answers: what might be wrong?
- Penetration testing is human-led and deep. A tester attempts to exploit weaknesses, chain them together and reach sensitive data, the way a real attacker would. It answers: what could an attacker actually do?
We offer external testing of your internet-facing systems (firewall, remote access, websites, email), internal testing from inside your network as if a device were compromised, and Microsoft 365 / cloud configuration reviews.
Which rules require security testing?
| Requirement | What it calls for |
|---|---|
| FTC Safeguards Rule | Annual penetration testing and vulnerability assessments at least every six months, unless you use continuous monitoring. Firms with fewer than 5,000 consumers are exempt from this item. |
| PCI DSS | Internal and external vulnerability scans, quarterly external ASV scans where your SAQ requires them, and penetration testing for merchants in scope. |
| HIPAA | Currently: risk analysis and periodic technical evaluation. HHS’s proposed update would require scans every six months and a pen test every 12 months. |
| Cyber insurance | Many carriers ask about vulnerability scanning and external exposure, and some scan applicants themselves. |
This is a general summary, not legal advice. We confirm which requirements apply during your free cybersecurity assessment.
Reports you can hand to an auditor
Every engagement ends with an executive summary in plain language, a technical findings list ranked by severity with evidence, specific remediation steps, and a retest to confirm fixes. Reports are written to be filed as compliance evidence, not just read once. If you are a managed client, we fix what we find; if not, the findings are yours to give any provider.
Signs it’s time for Penetration Testing & Vulnerability Scanning
- Your insurer, auditor or a client asked for a pen test report.
- You are covered by the FTC Safeguards Rule and have never been tested.
- You take card payments and do not know your scan status.
- You recently changed your firewall, network or cloud setup.
- You want proof your IT provider’s security actually works.
If two or more of these sound familiar, take the free security check or book a free cybersecurity assessment.
How our Penetration Testing & Vulnerability Scanning process works
Scope
Agree on targets, timing and rules of engagement in writing.
Test
Scanning and hands-on testing, scheduled to avoid disruption.
Report
Executive summary and severity-ranked technical findings.
Fix & retest
Remediation guidance or hands-on fixes, then a retest.
What’s included
- External vulnerability scanning of internet-facing systems
- Internal vulnerability scanning of computers, servers and network devices
- External and internal penetration testing
- Microsoft 365 and cloud configuration review
- Wi-Fi and network segmentation testing
- Severity-ranked findings with remediation steps
- Executive summary for owners, boards and auditors
- Retest after remediation
Who it’s for
- Firms covered by the FTC Safeguards Rule
- Healthcare practices preparing for HIPAA testing requirements
- Merchants with PCI scan obligations
- Businesses answering insurer or client security questionnaires
What affects the price
Every quote is flat and in writing. These are the factors that move the number:
| Factor | Why it matters |
|---|---|
| External footprint | Number of public IP addresses, websites and remote access points. |
| Internal scope | Number of computers, servers and network segments. |
| Cloud scope | Microsoft 365 or other cloud tenants included. |
| Frequency | One-time test vs. recurring scanning program. |
Testing for valley businesses
We test financial and insurance offices in Edwards and Avon, medical practices across the valley, and payment networks for restaurants and lodging in Vail and Beaver Creek.
“Todd has helped get our team protected at a level we had no idea existed. As an Insurance Agency, we know the importance of protecting our clients data, Todd has taken that to a new level!”
Frequently asked questions
How often should a small business get a penetration test?
At least annually, and after major changes such as a new office network, firewall or cloud migration. The FTC Safeguards Rule requires annual penetration testing for most covered firms, and HHS has proposed the same for HIPAA.
How often should we run vulnerability scans?
At minimum every six months under the FTC Safeguards Rule, quarterly for external PCI scans where required, and ideally monthly or continuously as part of managed security.
Will a penetration test disrupt our business?
Testing is scoped and scheduled in advance, avoids destructive techniques, and can run after hours. You approve the rules of engagement before anything starts.
How much does a penetration test cost for a small business?
Cost depends on scope: how many external addresses, internal systems and cloud accounts are included. We quote a fixed price after a short scoping call, and recurring scanning can be bundled into managed IT.
Can you test if another company manages our IT?
Yes. Independent testing is a good way to verify your current provider’s work. We coordinate timing with them so alerts are expected.
brand