Frequently Asked Questions: Security Audit & Penetration Testing

(01)What is the difference between a vulnerability scan and a penetration test?
A scan finds known vulnerabilities automatically. In a penetration test we additionally try, by hand, to chain and exploit vulnerabilities the way an attacker would. We use both.
(02)Will the audit disrupt our operations?
We agree test depth and test windows in writing beforehand. Risky tests are preferably run against a staging environment or closely coordinated with your team.
(03)Do we receive a certificate?
No, we do not certify. Our report documents scope, findings and measures and can serve as evidence for customers and auditors or as part of your NIS2 obligations.
(04)Do you also fix the vulnerabilities found?
On request, yes, as a separate engagement after scoping. Alternatively your team implements the measures and we check in a retest whether they work.
(05)What does a security audit cost?
Fixed price after scoping, quote within 48 hours. The effort depends mainly on the number and size of the systems tested.