Vulnerability assessment vs penetration test vs red team
KINNEX Team5 min read
Security testing terms are used loosely, which leads to buying the wrong thing.
Vulnerability assessment
An automated and reviewed scan for known weaknesses: missing patches, weak configurations, exposed services. It gives a broad list, ranked by severity, and is relatively quick and affordable. Good as a regular health check.
Penetration test
Skilled testers actively try to exploit weaknesses, within an agreed scope and time. They chain issues, prove what an attacker could reach and show the business impact. Types include external, internal, web application, mobile, wireless and cloud tests.
Red team exercise
A goal-driven simulation of a real attacker, often including phishing and physical access, testing people, process and detection together. It is for mature organisations that already have monitoring and response.
Choosing
- Early stage or first time: vulnerability assessment, then fix findings.
- Before a launch, a certification or a major change: penetration test of the relevant scope.
- Mature security team: red team or purple team exercise.
Getting value
Agree scope, rules and contacts in writing. Ask for an executive summary, technical detail, reproducible steps and fix guidance. Plan a retest to confirm fixes.
A note on delivery
Specialist testing is often best delivered by dedicated testers. We scope, coordinate and help remediate, bringing in the right specialist team under one contract where needed.