Penetration Test or Vulnerability Scan: What Your Company Really Needs
Find out whether your company needs a vulnerability scan or a pentest, how the costs compare and what the BSI recommends.

The vulnerability scan: Your automated early-warning system
To protect your company from cyberattacks, you do not have to hunt for new threats manually every day. An automated vulnerability scan takes on this work for you and forms the solid foundation of your continuous security management. The software probes your entire IT infrastructure and works like a digital alarm system that stays active around the clock. The system structures it finds are automatically checked against global vulnerability databases in order to surface known security gaps right away.
How it works and what it covers technically
The vulnerability scan searches your networks, servers, endpoints and applications for known weak spots. It identifies open ports that could serve as a way in for attackers, and it detects outdated software versions for which security updates already exist. Because modern attackers use automated tools to find unprotected systems on the internet, this automated protective shield is indispensable for you as a managing director or IT lead. Conventional antivirus software is no longer nearly enough today to detect complex security gaps in your infrastructure.
- Detection of open ports and misconfigurations in the network
- Identification of outdated software versions and missing security patches
- Automated matching against worldwide CVE databases (Common Vulnerabilities and Exposures)
- Regular, plannable reports so you can quickly remediate the most urgent risks
The cost-benefit ratio for mid-sized businesses
A major advantage of the vulnerability scan is how cost-effective it is. A professional scan is already achievable for German mid-sized businesses from 2,000 euros net[1]. For that budget you get a comprehensive and systematic review of your entire digital attack surface. This makes the scan an extremely cost-efficient way to meet the requirement for a regular review of IT security. If you want to know whether your company is affected by the new legal requirements, you can have your NIS2 obligation checked directly.
For lasting, gap-free protection, however, a continuous approach is advisable. With the CAVRIX Cybersecurity service you benefit from an integrated security concept that combines proactive vulnerability management directly with continuous monitoring. That way you make sure newly emerging security gaps are detected and fixed immediately, rather than only at the next scheduled review date.
The penetration test: A smart, simulated hacker attack
A penetration test (pentest for short) is not an automated tool that rigidly works through a list of known vulnerabilities. Instead, it is a controlled but realistic attack on your IT infrastructure, carried out manually by certified security experts. These ethical hackers deliberately put themselves in the position of cybercriminals in order to actively track down and exploit security gaps. For managing directors of German mid-sized businesses, this approach is crucial for testing the company's actual resilience and defusing existential security risks in good time.
The three test methods at a glance
- Black-box test: The testers receive no information whatsoever about your IT infrastructure in advance. They simulate an external attacker who first has to work their way in.
- Grey-box test: The experts have access to basic information, for example user accounts for internal systems. This simulates attacks by your own employees or partners.
- White-box test: Here the pentesters get full insight into the system architecture and the source code. This method is especially thorough, since deeply buried vulnerabilities are analysed as well.
A structured process based on BSI standards
To achieve reliable and reproducible results, professional pentests follow established standards such as the practical guide from the German Federal Office for Information Security (BSI). The structured process is divided into five phases: preparation, information gathering, assessment and selection of attack targets, active intrusion attempts and the final analysis. Such a methodical approach prevents unplanned system outages and ensures that all critical areas are examined systematically. This also helps your company minimise the personal liability of management and reliably comply with legal requirements such as the NIS2 directive.
Human logic beats rigid algorithms
Why is an automated tool not enough? Automated software scans are excellent at finding known patterns and obvious misconfigurations. But they fail where complex logic errors and creative chains of seemingly harmless vulnerabilities come into play. A human pentester combines different findings, exploits human weaknesses through social engineering or overcomes protective measures via unconventional paths. This creative human intelligence makes the decisive difference when it comes to fending off sophisticated attacks before they can do any damage. Within a modern security strategy, such as the one CAVRIX offers with its Cybersecurity service, the manual pentest is the perfect complement to continuous automated monitoring.
Comparing the costs: What does IT security cost for a mid-sized business?
Security assessments have to be affordable and predictable for mid-sized companies so you can make a sound risk-management decision. As a managing director or IT lead, you often face the challenge of using a limited budget as effectively as possible. Yet effective protection does not have to be an incalculable financial black box. By clearly distinguishing between automated scans and manual penetration tests, you can steer your investments in a targeted way. While continuous scans provide broad baseline monitoring, targeted manual tests uncover the critical routes of intrusion. This creates not only security but also helps you comply with legal requirements.
Automated scans: The low-cost, permanent protection
An automated vulnerability scan is the ideal entry point for systematically checking your IT infrastructure for known security gaps. These tools look for outdated software, open ports and misconfigurations across the entire network. Because the process runs largely software-driven, the costs are manageable. A professional vulnerability scan for a mid-sized business starts at around 2,000 euros net[1]. With this budget you get a solid overview of your attack surface and can immediately close the most urgent technical gaps before attackers exploit them. For continuous monitoring, CAVRIX offers integrated vulnerability management as part of its Cybersecurity service area, automating these scans.
Manual penetration tests: Targeted in-depth review with expert know-how
When it comes to highly critical applications, complex networks or compliance with strict NIS2 requirements, an automated review is not enough. This is where the manual penetration test (pentest) comes in. Certified security experts simulate targeted attacks to track down logic errors and complex security gaps. The cost of such tests depends heavily on scope and complexity. In the DACH region, daily rates for specialised auditors usually range between 1,200 and 2,000 euros. A targeted basic pentest for a network or a web app starts at about 5,400 euros[2]. For an in-depth review of extended IT structures including cloud services and VPN access in a mid-sized business, you should plan a budget of 10,000 to 25,000 euros.
| Type of assessment | Typical budget range (net) | Frequency | Focus |
|---|---|---|---|
| Automated vulnerability scan | From 2,000 euros | Regularly (e.g. monthly) | Broad network infrastructure, known CVE security gaps |
| Basic penetration test | From 5,400 euros | Annually or after major system changes | Targeted systems, web applications, APIs |
| Comprehensive penetration test | 10,000 to 25,000 euros | Annually or for regulatory compliance | Entire IT landscape, Active Directory, cloud, VPN paths |
The measurable return on investment (ROI) of IT security
Every euro you invest in a vulnerability scan or pentest reduces the risk of an existence-threatening security incident. The real economic lever lies in avoiding operational downtime, data loss and expensive incident-response engagements. If malware paralyses your production or customer data is stolen, the cost of recovery exceeds the price of a preventive assessment many times over. Another commercial advantage: many insurers require documented security assessments in order to pay out at all in the event of a claim. So with regular scans and tests you not only protect your company but also secure the coverage of your cyber insurance. While a pentest is a point-in-time check, professional day-to-day support ensures continuous stability. You can find an overview of ongoing operating costs in our guide to the cost of managed IT. With the integrated modules for Cybersecurity and Compliance from CAVRIX, you get continuous monitoring and make your security measures verifiable and audit-proof at any time.
When do you need which? The ideal decision guide
Security gaps put the operation of your company at risk and, in the worst case, can lead to costly outages. But do you have to hire an expensive team of external hackers straight away, or is an automated tool for regular checks enough? The answer depends heavily on your current starting point, your IT infrastructure and the legal requirements. For German mid-sized businesses, a pragmatic approach is needed that weighs costs and benefits sensibly. Rather than seeing the two methods as competitors, you should combine them strategically to achieve seamless and affordable protection.
Vulnerability scans: The foundation for continuous protection
A vulnerability scan runs fully automatically and regularly checks your servers, networks and endpoints for known security gaps[3]. For German mid-sized businesses, this method is ideal for achieving broad coverage without much staffing effort. If you use our Cybersecurity service, such automated checks are already firmly built into your day-to-day security concept. They uncover classic mistakes such as outdated software versions or wrong configurations before attackers can exploit them. Combined with our Managed IT service, which takes care of automatically applying security patches, you close the most dangerous points of entry extremely quickly.
| Assessment criterion | Vulnerability scan | Penetration test |
|---|---|---|
| Test method | Automated using specialised software | Manual by certified ethical hackers |
| Test depth | Broad analysis of known vulnerabilities without exploitation | Deep analysis including active exploitation of gaps |
| Frequency | Continuous, for example weekly or monthly | Event-driven or regular, usually once a year |
| Target area | Entire IT infrastructure and all endpoints | Especially sensitive or exposed systems |
Penetration tests: When manual in-depth reviews are indispensable
Unlike the automated scan, a penetration test simulates a real, targeted attack by human experts[3]. This manual effort is always necessary when highly sensitive systems are involved. Are you planning the go-live of your own web application or a new customer portal, for example? Then a pentest beforehand is strongly recommended. You should also have your environment thoroughly put through its paces by experts after far-reaching changes to your IT infrastructure or major system updates. That way you make sure the changes have not created new logical points of entry that a pure scan tool would overlook.
Combining security and compliance cleverly
The right mix is what matters. While continuous scans catch the daily background noise of threats, regular pentests provide in-depth evidence of how robust your defences are. This is also important for your company's financial protection, since modern cyber insurers demand ever stricter checks before settling a claim. With our holistic Cybersecurity service and the integrated modules for Compliance, we make sure your operation stays optimally protected and regulatory requirements are met. You can quickly and easily check whether your company is regulated at all via our guide to the NIS2 obligation. Through the intuitive Command Center, you keep full control over your current security status at any time, in chat or by email.
NIS2, ISO 27001 and GDPR: Regulatory obligations in focus
The legal requirements for IT security among German mid-sized businesses are tightening rapidly. Whether new directives at European level or established national standards: as a managing director or IT lead, you now face the challenge of not only ensuring the security of your systems in theory but also proving it seamlessly. Manual penetration tests and automated vulnerability scans are no longer optional extras here, but the most important tools for meeting the increased documentation obligations and effectively minimising liability risks.
Documentation obligations under the NIS2 directive
The NIS2 directive explicitly puts vulnerability management at the centre of European cybersecurity regulation[4]. Affected companies must demonstrate that they carry out regular risk analyses and establish technical security reviews. Anyone who neglects these obligations faces not only substantial fines for the company but also direct personal liability for management in a serious case. A regular penetration test is regarded as the gold standard here for proving to supervisory authorities, beyond any doubt, the actual effectiveness of the defensive measures you have put in place.
Continuous vulnerability monitoring for ISO 27001
For certification to ISO 27001, a systematic process for detecting technical vulnerabilities is indispensable. The standard requires in Annex A that known security gaps be proactively identified, assessed and remediated[5]. While there are clear differences in legal bindingness when comparing NIS2 vs. ISO 27001, the goal remains identical: security risks must be minimised continuously. An automated vulnerability scan gives you the necessary continuous monitoring of the entire infrastructure, while targeted penetration tests deeply examine especially critical systems.
Avoiding GDPR fines through risk management
Data protection also calls for technical vigilance. Under Article 32 of the GDPR, you are obliged to establish a procedure for regularly reviewing and evaluating the effectiveness of your technical and organisational measures[6]. If sensitive customer or employee data leaks through an undetected security gap, drastic fines loom. By combining ongoing scans and in-depth penetration tests, you show the authorities that your company practises proactive risk management. This is exactly where our CAVRIX services come in: with Compliance we capture your evidence automatically for upcoming audits, while Cybersecurity ensures the ongoing protection and vulnerability monitoring of your IT infrastructure.
- Legal certainty: Seamless fulfilment of the documentation obligations under NIS2, ISO 27001 and GDPR.
- Reduced liability: Protection of management from personal liability in the event of a claim by proving proactive audits.
- Full transparency: Automated capture of all relevant security data and reports for auditors.
- Efficient combination: Continuous protection through automated vulnerability scans combined with in-depth annual penetration tests.
The perfect combination: Defense in depth for your company
Information security is not a one-off project but a continuous process. To protect your IT infrastructure effectively against modern threats, it is not enough to rely on a single security measure. Real cyber resilience within a defense-in-depth approach only emerges when you strategically combine automated vulnerability scans and manual penetration tests. Such a combination is the foundation for professional cybersecurity and protects your systems comprehensively against costly attacks.
Automated scans as a daily routine
Automated vulnerability scans should be established as a fixed part of your routine. They run in the background and continuously check your networks, endpoints and cloud interfaces for known security gaps or outdated software versions. As soon as new vulnerabilities become publicly known, the system raises the alarm immediately. This gives your IT team the chance to apply updates and patches in a targeted way before attackers can exploit these points of entry for attacks such as ransomware.
The annual penetration test as recommended by the BSI
A manual penetration test goes considerably deeper and looks at the system from the perspective of a real hacker. The German Federal Office for Information Security (BSI) recommends carrying out such comprehensive tests at least once a year as well as after every major change to your infrastructure[7]. Experienced penetration testers use creative methods to track down complex logic errors and link seemingly harmless vulnerabilities into a dangerous attack chain. That uncovers weak spots no automated scanner would ever find.
- Daily routine: Continuous vulnerability scans monitor the IT infrastructure automatically around the clock for known vulnerabilities.
- Regular pentests: Annual manual penetration tests simulate creative attacks and assess the actual resilience of your defences.
- Efficient remediation: Automated detection provides the basis for fast patches, while the manual pentest delivers detailed reports for deeper security improvements.
- Lower liability risk: Combining both methods meets legal obligations and protects managing directors from personal liability in the event of security incidents.
To implement this demanding strategy without your own IT specialists in your business, you can rely on the support of experts. With the CAVRIX Cybersecurity service, this continuous monitoring is integrated seamlessly into your operational processes. That way your business benefits from automated scans while an optimal cost-benefit ratio for mid-sized companies is maintained at the same time.
Frequently asked questions
What is the main difference between a vulnerability scan and a pentest?
A vulnerability scan runs fully automatically and systematically searches for known flaws across your entire IT. It finds the broad mass of vulnerabilities from around 2,000 euros net. A penetration test, on the other hand, is carried out manually by experts. They simulate targeted hacker attacks to find out whether and how deeply attackers can actually penetrate your networks.
How often should my company have a penetration test carried out?
For critical systems, the BSI recommends running one at least once a year. In addition, you should always commission a manual pentest whenever you have made major changes to your IT infrastructure, a new business-critical web app goes live or the regulatory requirements for you change.
What does a professional penetration test cost for a mid-sized business?
The cost depends heavily on the scope of the systems to be tested. A guided, manual penetration test starts at specialised providers from a fixed price of around 5,400 euros net. More complex tests for sprawling infrastructures can cost up to 25,000 euros or more, depending on the effort and number of test days.
Is a penetration test mandatory for NIS2 compliance?
The NIS2 directive requires affected companies to prove the effectiveness of their risk-management measures. In practice, a regular penetration test is regarded as the gold standard for demonstrating this effectiveness to auditors reliably and seamlessly.
Does an automated vulnerability scan replace a manual pentest?
No, the two methods complement each other and should be combined. A scan continuously covers new, known gaps, while the pentest uncovers complex attack paths that can only be found through human logic and creativity. That is why the BSI expressly recommends both methods.