We run wholesale ordering software and a B2B portal out of Valencia with a team of 12. Last week, a major enterprise client requested a comprehensive security audit report from us ahead of contract renewal. A local consultancy told us they could periodically scan the system using automated vulnerability assessment tools and provide reports, quoting 1,400 EUR for an annual package.
An independent consultant we spoke with, however, said these scans would just scratch the surface and that what the client actually expects is a manual penetration test, quoting 3,500 EUR for a one-off engagement. The price difference is pretty significant for a small company like ours.
Can automated vulnerability scanning replace a penetration test on its own, or do they serve completely different purposes? To make the best use of our budget, which one should we do first?